# PegaProx Requirements
# Install with: pip install -r requirements.txt

# === Core (Required) ===
flask>=3.1.3
flask-cors>=6.0.0
flask-sock>=0.6.0
flask-compress>=1.14
werkzeug>=3.1.6
requests>=2.34.0
requests-toolbelt>=1.0.0
urllib3>=2.7.0
dnspython>=2.7.0

# === Encryption & Security ===
# These three interlock — bump together: pyopenssl caps cryptography <51, fido2 caps <52.
cryptography>=50.0.0,<52
pyopenssl>=26.4.0
argon2-cffi>=23.0.0
pyasn1>=0.6.4
# Full-DB encryption; prebuilt wheels are Linux x86_64 only — elsewhere PegaProx falls back
# to plain SQLite + Fernet field encryption (see docs/SECURITY.md).
sqlcipher3-binary>=0.6.0; sys_platform == "linux" and platform_machine == "x86_64"

# === SSH & Console ===
paramiko>=4.0.0
websockets>=11.0
websocket-client>=1.6.0
h11>=0.16.0

# === Performance (Recommended) ===
gevent>=25.4.1
gevent-websocket>=0.10.0

# === Two-Factor Auth ===
pyotp>=2.9.0
qrcode[pil]>=7.4.0
pillow>=12.3.0
# WebAuthn / FIDO2 hardware tokens (optional; auto-disabled if the import fails).
# 2.2.1 is the first fido2 whose cryptography cap is <52 — see the crypto pins above.
fido2>=2.2.1

# === LDAP Auth ===
ldap3>=2.9.0

# === OIDC JWT Verification ===
PyJWT[crypto]>=2.13.0

# === ESXi Migration (Optional) ===
pyvmomi>=8.0.0

# === XCP-ng Integration (Optional) ===
XenAPI>=23.14.0

# === Hardened XML parsing ===
defusedxml>=0.7.1

# === Transitive pins (scanner hygiene; newer versions pulled automatically) ===
setuptools>=83.0.0
zipp>=3.19.1
idna>=3.15
