dfG|dZddlZ ejddZn #e$rdZYnwxYw ddlmZn#e$r ddlmZYnwxYw e n#e $r e Z e e fZ YnwxYw en #e $reZYnwxYw en #e $reZYnwxYwdZdZd Zd ZGd d eZd ZdedfdZdedddfdZdedddfdZdedfdZdZdZeZeZ dS)a phpserialize ~~~~~~~~~~~~ a port of the ``serialize`` and ``unserialize`` functions of php to python. This module implements the python serialization interface (eg: provides `dumps`, `loads` and similar functions). Usage ===== >>> from phpserialize import * >>> obj = dumps("Hello World") >>> loads(obj) 'Hello World' Due to the fact that PHP doesn't know the concept of lists, lists are serialized like hash-maps in PHP. As a matter of fact the reverse value of a serialized list is a dict: >>> loads(dumps(range(2))) {0: 0, 1: 1} If you want to have a list again, you can use the `dict_to_list` helper function: >>> dict_to_list(loads(dumps(range(2)))) [0, 1] It's also possible to convert into a tuple by using the `dict_to_tuple` function: >>> dict_to_tuple(loads(dumps((1, 2, 3)))) (1, 2, 3) Another problem are unicode strings. By default unicode strings are encoded to 'utf-8' but not decoded on `unserialize`. The reason for this is that phpserialize can't guess if you have binary or text data in the strings: >>> loads(dumps(u'Hello W\xf6rld')) 'Hello W\xc3\xb6rld' If you know that you have only text data of a known charset in the result you can decode strings by setting `decode_strings` to True when calling loads: >>> loads(dumps(u'Hello W\xf6rld'), decode_strings=True) u'Hello W\xf6rld' Dictionary keys are limited to strings and integers. `None` is converted into an empty string and floats and booleans into integers for PHP compatibility: >>> loads(dumps({None: 14, 42.23: 'foo', True: [1, 2, 3]})) {'': 14, 1: {0: 1, 1: 2, 2: 3}, 42: 'foo'} It also provides functions to read from file-like objects: >>> from StringIO import StringIO >>> stream = StringIO('a:2:{i:0;i:1;i:1;i:2;}') >>> dict_to_list(load(stream)) [1, 2] And to write to those: >>> stream = StringIO() >>> dump([1, 2], stream) >>> stream.getvalue() 'a:2:{i:0;i:1;i:1;i:2;}' Like `pickle` chaining of objects is supported: >>> stream = StringIO() >>> dump([1, 2], stream) >>> dump("foo", stream) >>> stream.seek(0) >>> load(stream) {0: 1, 1: 2} >>> load(stream) 'foo' This feature however is not supported in PHP. PHP will only unserialize the first object. Array Serialization =================== Starting with 1.2 you can provide an array hook to the unserialization functions that are invoked with a list of pairs to return a real array object. By default `dict` is used as array object which however means that the information about the order is lost for associative arrays. For example you can pass the ordered dictionary to the unserilization functions: >>> from collections import OrderedDict >>> loads('a:2:{s:3:"foo";i:1;s:3:"bar";i:2;}', ... array_hook=OrderedDict) collections.OrderedDict([('foo', 1), ('bar', 2)]) Object Serialization ==================== PHP supports serialization of objects. Starting with 1.2 of phpserialize it is possible to both serialize and unserialize objects. Because class names in PHP and Python usually do not map, there is a separate `object_hook` parameter that is responsible for creating these classes. For a simple test example the `phpserialize.phpobject` class can be used: >>> data = 'O:7:"WP_User":1:{s:8:"username";s:5:"admin";}' >>> user = loads(data, object_hook=phpobject) >>> user.username 'admin' >>> user.__name__ 'WP_User' An object hook is a function that takes the name of the class and a dict with the instance data as arguments. The instance data keys are in PHP format which usually is not what you want. To convert it into Python identifiers you can use the `convert_member_dict` function. For more information about that, have a look at the next section. Here an example for a simple object hook: >>> class User(object): ... def __init__(self, username): ... self.username = username ... >>> def object_hook(name, d): ... cls = {'WP_User': User}[name] ... return cls(**d) ... >>> user = loads(data, object_hook=object_hook) >>> user.username 'admin' To serialize objects you can use the `object_hook` of the dump functions and return instances of `phpobject`: >>> def object_hook(obj): ... if isinstance(obj, User): ... return phpobject('WP_User', {'username': obj.username}) ... raise LookupError('unknown object') ... >>> dumps(user, object_hook=object_hook) 'O:7:"WP_User":1:{s:8:"username";s:5:"admin";}' PHP's Object System =================== The PHP object system is derived from compiled languages such as Java and C#. Attributes can be protected from external access by setting them to `protected` or `private`. This does not only serve the purpose to encapsulate internals but also to avoid name clashes. In PHP each class in the inheritance chain can have a private variable with the same name, without causing clashes. (This is similar to the Python `__var` name mangling system). This PHP class:: class WP_UserBase { protected $username; public function __construct($username) { $this->username = $username; } } class WP_User extends WP_UserBase { private $password; public $flag; public function __construct($username, $password) { parent::__construct($username); $this->password = $password; $this->flag = 0; } } Is serialized with a member data dict that looks like this: >>> data = { ... ' * username': 'the username', ... ' WP_User password': 'the password', ... 'flag': 'the flag' ... } Because this access system does not exist in Python, the `convert_member_dict` can convert this dict: >>> d = convert_member_dict(data) >>> d['username'] 'the username' >>> d['password'] 'the password' The `phpobject` class does this conversion on the fly. What is serialized is the special `__php_vars__` dict of the class: >>> user = phpobject('WP_User', data) >>> user.username 'the username' >>> user.username = 'admin' >>> user.__php_vars__[' * username'] 'admin' As you can see, reassigning attributes on a php object will try to change a private or protected attribute with the same name. Setting an unknown one will create a new public attribute: >>> user.is_admin = True >>> user.__php_vars__['is_admin'] True To convert the phpobject into a dict, you can use the `_asdict` method: >>> d = user._asdict() >>> d['username'] 'admin' Python 3 Notes ============== Because the unicode support in Python 3 no longer transparently handles bytes and unicode objects we had to change the way the decoding works. On Python 3 you most likely want to always decode strings. Because this would totally fail on binary data phpserialize uses the "surrogateescape" method to not fail on invalid data. See the documentation in Python 3 for more information. Changelog ========= 1.3 - added support for Python 3 1.2 - added support for object serialization - added support for array hooks 1.1 - added `dict_to_list` and `dict_to_tuple` - added support for unicode - allowed chaining of objects like pickle does :copyright: 2007-2012 by Armin Ronacher. license: BSD Nsurrogateescapestrict)StringIO)BytesIOz,Armin Ronacher z1.3) phpobjectconvert_member_dict dict_to_list dict_to_tupleloadloadsdumpdumps serialize unserializecZ|dddkr|ddd}|S)N )split)names l/builddir/build/BUILD/imunify360-venv-2.3.5/opt/imunify360/venv/lib/python3.11/site-packages/phpserialize.py_translate_member_namer#s0 BQBx3zz$""2& Kc<eZdZdZdZd dZdZdZdZdZ d Z dS) rz5Simple representation for PHP objects. This is used )__name__ __php_vars__Nc~|i}t|d|t|d|dS)Nrr)object __setattr__)selfrds r__init__zphpobject.__init__-sB 9A4T222433333rc*t|jS)z?Returns a new dictionary from the data with Python identifiers.)rrr!s r_asdictzphpobject._asdict3s"4#4555rcv|jD]\}}t||kr||fcSdSN)ritemsr)r!rkeyvalues r_lookup_php_varzphpobject._lookup_php_var7sV+1133 " "JC%c**d22Ez!!!3 " "rc^||}||dSt|)Nr)r,AttributeError)r!rrvs r __getattr__zphpobject.__getattr__<s1  ! !$ ' ' >a5LT"""rcX||}||d}||j|<dS)Nr)r,r)r!rr+r/s rr zphpobject.__setattr__Bs6  ! !$ ' ' >a5D"'$rcd|jdS)Nz )rr%s r__repr__zphpobject.__repr__Hs#'===22rr() r __module__ __qualname____doc__ __slots__r#r&r,r0r r4rrrr)s~??,I4444 666""" ### ((( 33333rrcXtd|DS)aConverts the names of a member dict to Python syntax. PHP class data member names are not the plain identifiers but might be prefixed by the class name if private or a star if protected. This function converts them into standard Python identifiers: >>> convert_member_dict({"username": "user1", " User password": ... "default", " * is_active": True}) {'username': 'user1', 'password': 'default', 'is_active': True} c3>K|]\}}t||fVdSr()r).0kvs r z&convert_member_dict..Vs4EE41a'**A.EEEEEEr)dictr)r"s rrrLs) EE17799EEE E EErzutf-8c2fd|dS)zReturn the PHP-serialized representation of the object as a string, instead of writing it to a file like `dump` does. On Python 3 this returns bytes objects, on Python 3 this returns bytestrings. c|r]t|ttttfrd|zdSt|t r|}t|tr| }t}| d| tt|d| d| || d| S|dStdt|z|dSt|trd |zdSt|ttfrd |zdSt|trd |zdSt|t r|}t|tr| }t}| d| tt|d| d| || d| St|tt t"frg}t|t"r|}nt'|}|D]C\}}||d ||d Dddtt|ddd|dgSt|t,r6d|jd ddz|jd ddzS  |d Stdt|z)Nzi:%i;latin1ss:s:"s";ss:0:"";zcan't serialize %r as keysN;zb:%i;zi:%s;zd:%s;TFrsa:s:{}Orrzcan't serialize %r) isinstanceintlongfloatboolencode basestringunicoderwritestrlengetvalue TypeErrortypelisttupler@r) enumerateappendjoinrrr) objkeypos encoded_objsoutiterabler*r+ _serializecharseterrors object_hooks rr`zdumps.._serialize^s : ?#T5$788 8# --h777#z** $! c7++>"%**Wf"="=KIIC ,,--44X>>??? $$$zz||#{!z8499DEE E{u#t$$ 8# --h777#T{++ 8# --h777#u%% 8# --h777#z** $! c7++>"%**Wf"="=KIIC ,,--44X>>??? $$$zz||##eT233 c4((."yy{{HH(~~H"*99JCJJzz#t44555JJzz%778888xxCMM((22HHSMM !#y)) ?jjt<??&!z++c"2"2E:::1DII=>> >rFr9)datararbrcr`s ```@rrrYsC ;?;?;?;?;?;?;?;?z :dE " ""rFc x tfdfd fdf d  S)a\Read a string from the open file object `fp` and interpret it as a data stream of PHP-serialized objects, reconstructing and returning the original object hierarchy. `fp` must provide a `read()` method that takes an integer argument. Both method should return strings. Thus `fp` can be a file object opened for reading, a `StringIO` object (`BytesIO` on Python 3), or any other custom object that meets this interface. `load` will read exactly one object from the stream. See the docstring of the module for this chained behavior. If an object hook is given object-opcodes are supported in the serilization format. The function is called with the class name and a dict of the class data members. The data member names are in PHP format which is usually not what you want. The `simple_object_hook` function can convert them to Python identifier names. If an `array_hook` is given that function is called with a list of pairs for all array items. This can for example be set to `collections.OrderedDict` for an ordered, hashed dictionary. Nct|}||krtd|d|dS)Nzfailed expectation, expected z got )readrQ ValueError)er>fps r_expectzload.._expectsC GGCFFOO 66*AANOO O 6rcg} d}||krn'|std||Cd|S)Nrzunexpected end of streamr)rgrhrXrY)delimbufcharrjs r _read_untilzload.._read_untilsh 771::Du}} = !;<<< JJt     xx}}rctddz}dg}t}t|D]6}}|tur|}|||ft}7d|S)N:r{rE)rHEllipsisxrangerX)r)result last_itemidxitemrkrp _unserializes r _load_arrayzload.._load_arraysKK%%&&*  %== % %C<>>DH$$  y$/000$   rc d}|dkr ddS|dvrSdd}|dkrt|S|dkrt|St|dkS|d krsdtd}d  |}d  r| }d|S|d krdS|d kr t d dtd}d  |}d r| } |t St d)Nrn;sidbrridrs"aoz7object in serialization dump but object_hook not given.s":zunexpected opcode)rglowerrHrJdecoderhr@)type_rdlength name_lengthrrkr{rp array_hookradecode_stringsrbrjrcs rrzzload.._unserializes   "" D== GDMMM4 F?? GDMMM;t$$D}}4yy }}T{{"t99> ! D== GDMMMT**++F GDMMM776??D GDMMM 4{{7F33 GDMMMK D== GDMMM:kkmm,, , D==" ":;;; GDMMMkk$//00K GDMMM77;''D GENNN 4{{7F33;tT++--%8%899 9,---r)r@) rjrarbrrcrrkr{rprzs ``````@@@@rr r s0 PPPPP            &.&.&.&.&.&.&.&.&.&.&.&.&.P <>>rcDtt||||||S)zRead a PHP-serialized object hierarchy from a string. Characters in the string past the object's representation are ignored. On Python 3 the string must be a bytestring. )r r)rdrarbrrcrs rr r s)  wZ ) ))rcP|t||||dS)akWrite a PHP-serialized representation of obj to the open file object `fp`. Unicode strings are encoded to `charset` with the error handling of `errors`. `fp` must have a `write()` method that accepts a single string argument. It can thus be a file object opened for writing, a `StringIO` object (or a `BytesIO` object on Python 3), or any other custom object that meets this interface. The `object_hook` is called for each unknown object and has to either raise an exception if it's unable to convert the object or return a value that is serializable (such as a `phpobject`). N)rOr)rdrjrarbrcs rr r s*HHU4&+ 6 677777rct fdttDS#t$rt dwxYw)z%Converts an ordered dict into a list.c g|] }| Sr9r9)r<xr"s r z dict_to_list..$s---!---rzdict is not a sequence)r@rurQKeyErrorrhrAs`rr r se QA3----fSVVnn---- 33312223s ':Ac:tt|S)z&Converts an ordered dict into a tuple.)rVr rAs rr r )s a ! !!r)!r7codecs lookup_errordefault_errors LookupErrorrr ImportErroriorN NameErrorrPbytesrMrIrHrurange __author__ __version____all__rrrrrr r r r r rrr9rrrs]||z F)***&NNNNN&,,,,,,,&&&%%%%%%%%& GGGJJJ DD DDD FF FFF<   I 3 3 3 3 3 3 3 3F F F F DB#B#B#B#J^EdbbbbJ ut))))#>t8888"333"""   sN%%0 >>A AAAA$#A$(A++A54A5