# Maintainer: Szilárd Pfeiffer <coroner@pfeifferszilard.hu>

pkgbase=cryptolyzer
pkgname=('python-cryptolyzer' 'cryptolyzer')
pkgver=1.6.0
pkgrel=1
arch=('any')
url='https://gitlab.com/coroner/cryptolyzer'
license=('MPL-2.0')
makedepends=('python-build' 'python-installer' 'python-setuptools' 'python-setuptools-scm'
             'python-wheel')
checkdepends=('python-asn1crypto' 'python-attrs' 'python-beautifulsoup4' 'python-colorama'
              'python-cryptoparser' 'python-dateutil' 'python-dnspython'
              'python-pycryptodomex>=3.19' 'python-pyfakefs' 'python-requests' 'python-urllib3')

_builddir="${pkgbase}-v${pkgver}"

source=("${pkgbase}-${pkgver}.tar.gz::${url}/-/archive/v${pkgver}/${_builddir}.tar.gz")
sha256sums=('713ce661c29d401803c61d7b54ccc56bab7131d0e0f66387477eafc0578b8bb9')

build() {
  cd "${_builddir}"
  python -m build --wheel --no-isolation
  # Install once into a staging directory that both packages copy from.
  rm -rf "${srcdir}/stage"
  python -m installer --destdir="${srcdir}/stage" dist/*.whl
}

check() {
  cd "${_builddir}"
  local site_packages
  site_packages=$(python -c 'import sysconfig; print(sysconfig.get_paths()["purelib"])')
  # cryptolyzer reads its own distribution metadata on import, so the tests run
  # against the staged installation rather than the source tree.
  PYTHONPATH="${srcdir}/stage${site_packages}" \
  CRYPTOLYZER_TEST_SKIP_LIVE_SERVER=1 CRYPTOLYZER_TEST_SKIP_LIVE_DNS=1 \
  no_proxy=127.0.0.1,localhost \
      python -m unittest discover
}

package_python-cryptolyzer() {
  pkgdesc='Multi-protocol cryptographic configuration analyzer for TLS, SSH, IKE, DNS, and HTTP — alternative to testssl.sh and sslyze with Python API, 400+ cipher suites, vulnerability detection (FREAK, Logjam, ROBOT), and JA3/HASSH fingerprinting'
  depends=('python'
           'python-asn1crypto'
           'python-attrs'
           'python-beautifulsoup4'
           'python-colorama'
           'python-cryptoparser>=1.6.0'
           'python-dateutil'
           'python-dnspython'
           'python-pycryptodomex>=3.19'
           'python-requests'
           'python-urllib3')
  optdepends=('python-certvalidator: X.509 certificate chain validation, trust store check and revocation check')

  cp -a "${srcdir}/stage/." "${pkgdir}/"
  rm -rf "${pkgdir}/usr/bin"

  install -Dm644 "${srcdir}/${_builddir}/LICENSE.txt" \
    "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.txt"
}

package_cryptolyzer() {
  pkgdesc='Multi-protocol cryptographic configuration analyzer for TLS, SSH, IKE, DNS, and HTTP — alternative to testssl.sh and sslyze with Python API, 400+ cipher suites, vulnerability detection (FREAK, Logjam, ROBOT), and JA3/HASSH fingerprinting'
  depends=("python-cryptolyzer=${pkgver}-${pkgrel}")

  install -Dm755 "${srcdir}/stage/usr/bin/cryptolyze" "${pkgdir}/usr/bin/cryptolyze"

  install -Dm644 "${srcdir}/${_builddir}/LICENSE.txt" \
    "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.txt"
}
