Skip to main content

PyNameConstraintsBuilder

Struct PyNameConstraintsBuilder 

Source
pub struct PyNameConstraintsBuilder { /* private fields */ }
Expand description

Fluent builder for a NameConstraints extension value (OID 2.5.29.30, RFC 5280 §4.2.1.10).

The NameConstraints extension restricts the namespace within which all subject names in certificates issued by a CA must fall. Names in permittedSubtrees are allowed; names in excludedSubtrees are forbidden. When present in a CA certificate this extension MUST be marked critical.

Add permitted and excluded subtrees using the typed methods, then call :meth:build to obtain the DER bytes of the NameConstraints SEQUENCE — the content that goes inside the OCTET STRING wrapper in the Extension SEQUENCE.

The class is also available as the short alias synta.ext.NC.

DNS name conventions: prefix the domain with a leading dot (e.g. ".example.com") to constrain the entire subtree rooted at example.com; omit the dot to constrain only that exact host.

IP address constraints: pass address bytes concatenated with mask bytes — 8 bytes for IPv4 (e.g. b"\\xc0\\xa8\\x00\\x00\\xff\\xff\\x00\\x00" for 192.168.0.0/16) or 32 bytes for IPv6.

import synta.ext as ext

# Permit example.com DNS subtree and a private IP range;
# exclude a known-bad subdomain.
nc = ext.NC() \
    .permit_dns(".example.com") \
    .permit_rfc822(".example.com") \
    .permit_ip(b"\x0a\x00\x00\x00\xff\x00\x00\x00") \
    .exclude_dns(".evil.com") \
    .build()

Trait Implementations§

Source§

impl DerefToPyAny for PyNameConstraintsBuilder

Source§

impl ExtractPyClassWithClone for PyNameConstraintsBuilder

Source§

impl<'py> IntoPyObject<'py> for PyNameConstraintsBuilder

Source§

type Target = PyNameConstraintsBuilder

The Python output type
Source§

type Output = Bound<'py, <PyNameConstraintsBuilder as IntoPyObject<'py>>::Target>

The smart pointer type to use. Read more
Source§

type Error = PyErr

The type returned in the event of a conversion error.
Source§

fn into_pyobject( self, py: Python<'py>, ) -> Result<<Self as IntoPyObject<'_>>::Output, <Self as IntoPyObject<'_>>::Error>

Performs the conversion.
Source§

impl PyClass for PyNameConstraintsBuilder

Source§

type Frozen = False

Whether the pyclass is frozen. Read more
Source§

impl PyClassImpl for PyNameConstraintsBuilder

Source§

const IS_BASETYPE: bool = false

#[pyclass(subclass)]
Source§

const IS_SUBCLASS: bool = false

#[pyclass(extends=…)]
Source§

const IS_MAPPING: bool = false

#[pyclass(mapping)]
Source§

const IS_SEQUENCE: bool = false

#[pyclass(sequence)]
Source§

const IS_IMMUTABLE_TYPE: bool = false

#[pyclass(immutable_type)]
Source§

const RAW_DOC: &'static CStr = /// Fluent builder for a ``NameConstraints`` extension value (OID 2.5.29.30, /// RFC 5280 §4.2.1.10). /// /// The ``NameConstraints`` extension restricts the namespace within which all /// subject names in certificates issued by a CA must fall. Names in /// ``permittedSubtrees`` are allowed; names in ``excludedSubtrees`` are /// forbidden. When present in a CA certificate this extension MUST be marked /// critical. /// /// Add permitted and excluded subtrees using the typed methods, then call /// :meth:`build` to obtain the DER bytes of the ``NameConstraints`` SEQUENCE — /// the content that goes inside the OCTET STRING wrapper in the ``Extension`` /// SEQUENCE. /// /// The class is also available as the short alias ``synta.ext.NC``. /// /// **DNS name conventions:** prefix the domain with a leading dot (e.g. /// ``".example.com"``) to constrain the entire subtree rooted at /// ``example.com``; omit the dot to constrain only that exact host. /// /// **IP address constraints:** pass address bytes concatenated with mask bytes /// — 8 bytes for IPv4 (e.g. ``b"\\xc0\\xa8\\x00\\x00\\xff\\xff\\x00\\x00"`` /// for ``192.168.0.0/16``) or 32 bytes for IPv6. /// /// ```python,ignore /// import synta.ext as ext /// /// # Permit example.com DNS subtree and a private IP range; /// # exclude a known-bad subdomain. /// nc = ext.NC() \ /// .permit_dns(".example.com") \ /// .permit_rfc822(".example.com") \ /// .permit_ip(b"\x0a\x00\x00\x00\xff\x00\x00\x00") \ /// .exclude_dns(".evil.com") \ /// .build() /// ```

Docstring for the class provided on the struct or enum. Read more
Source§

const DOC: &'static CStr

Fully rendered class doc, including the text_signature if a constructor is defined. Read more
Source§

type BaseType = PyAny

Base class
Source§

type ThreadChecker = SendablePyClass<PyNameConstraintsBuilder>

This handles following two situations: Read more
Source§

type PyClassMutability = <<PyAny as PyClassBaseType>::PyClassMutability as PyClassMutability>::MutableChild

Immutable or mutable
Source§

type Dict = PyClassDummySlot

Specify this class has #[pyclass(dict)] or not.
Source§

type WeakRef = PyClassDummySlot

Specify this class has #[pyclass(weakref)] or not.
Source§

type BaseNativeType = PyAny

The closest native ancestor. This is PyAny by default, and when you declare #[pyclass(extends=PyDict)], it’s PyDict.
Source§

fn items_iter() -> PyClassItemsIter

Source§

fn lazy_type_object() -> &'static LazyTypeObject<Self>

Source§

fn dict_offset() -> Option<isize>

Source§

fn weaklist_offset() -> Option<isize>

Source§

impl PyClassNewTextSignature for PyNameConstraintsBuilder

Source§

const TEXT_SIGNATURE: &'static str = "()"

Source§

impl PyMethods<PyNameConstraintsBuilder> for PyClassImplCollector<PyNameConstraintsBuilder>

Source§

fn py_methods(self) -> &'static PyClassItems

Source§

impl PyTypeInfo for PyNameConstraintsBuilder

Source§

const NAME: &'static str = "NameConstraintsBuilder"

Class name.
Source§

const MODULE: Option<&'static str> = ::core::option::Option::None

Module name, if any.
Source§

fn type_object_raw(py: Python<'_>) -> *mut PyTypeObject

Returns the PyTypeObject instance for this type.
Source§

fn type_object(py: Python<'_>) -> Bound<'_, PyType>

Returns the safe abstraction over the type object.
Source§

fn is_type_of(object: &Bound<'_, PyAny>) -> bool

Checks if object is an instance of this type or a subclass of this type.
Source§

fn is_exact_type_of(object: &Bound<'_, PyAny>) -> bool

Checks if object is an instance of this type.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<'py, T> IntoPyObjectExt<'py> for T
where T: IntoPyObject<'py>,

Source§

fn into_bound_py_any(self, py: Python<'py>) -> Result<Bound<'py, PyAny>, PyErr>

Converts self into an owned Python object, dropping type information.
Source§

fn into_py_any(self, py: Python<'py>) -> Result<Py<PyAny>, PyErr>

Converts self into an owned Python object, dropping type information and unbinding it from the 'py lifetime.
Source§

fn into_pyobject_or_pyerr(self, py: Python<'py>) -> Result<Self::Output, PyErr>

Converts self into a Python object. Read more
Source§

impl<T> PyErrArguments for T
where T: for<'py> IntoPyObject<'py> + Send + Sync,

Source§

fn arguments(self, py: Python<'_>) -> Py<PyAny>

Arguments for exception
Source§

impl<T> PyTypeCheck for T
where T: PyTypeInfo,

Source§

const NAME: &'static str = T::NAME

👎Deprecated since 0.27.0:

Use ::classinfo_object() instead and format the type name at runtime. Note that using built-in cast features is often better than manual PyTypeCheck usage.

Name of self. This is used in error messages, for example.
Source§

fn type_check(object: &Bound<'_, PyAny>) -> bool

Checks if object is an instance of Self, which may include a subtype. Read more
Source§

fn classinfo_object(py: Python<'_>) -> Bound<'_, PyAny>

Returns the expected type as a possible argument for the isinstance and issubclass function. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> Ungil for T
where T: Send,