§
    (ê[fÝ  ã                   óJ   — d dl mZ ddlmZ ddlmZmZ  G d„ de¦  «        ZdS )é    )Údefault_json_headersé   )ÚTokenEndpoint)ÚInvalidRequestErrorÚUnsupportedTokenTypeErrorc                   ó4   — e Zd ZdZdZd„ Zd„ Zd„ Zd„ Zd„ Z	dS )	ÚRevocationEndpointz†Implementation of revocation endpoint which is described in
    `RFC7009`_.

    .. _RFC7009: https://tools.ietf.org/html/rfc7009
    Ú
revocationc                 óÚ   — |                       ||¦  «         |                      |j        d         |j                             d¦  «        ¦  «        }|r|                     |¦  «        r|S dS dS )a…  The client constructs the request by including the following
        parameters using the "application/x-www-form-urlencoded" format in
        the HTTP request entity-body:

        token
            REQUIRED.  The token that the client wants to get revoked.

        token_type_hint
            OPTIONAL.  A hint about the type of the token submitted for
            revocation.
        ÚtokenÚtoken_type_hintN)Úcheck_paramsÚquery_tokenÚformÚgetÚcheck_client©ÚselfÚrequestÚclientr   s       úU/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth2/rfc7009/revocation.pyÚauthenticate_tokenz%RevocationEndpoint.authenticate_token   s}   € ð 	×Ò˜' 6Ñ*Ô*Ð*Ø× Ò  ¤¨gÔ!6¸¼×8HÒ8HÐIZÑ8[Ô8[Ñ\Ô\ˆØð 	�U×'Ò'¨Ñ/Ô/ð 	ØˆLð	ð 	ð 	ð 	ó    c                 óž   — d|j         vrt          ¦   «         ‚|j                              d¦  «        }|r|| j        vrt	          ¦   «         ‚d S d S )Nr   r   )r   r   r   ÚSUPPORTED_TOKEN_TYPESr   )r   r   r   Úhints       r   r   zRevocationEndpoint.check_params#   sb   € Ø˜'œ,Ð&Ð&Ý%Ñ'Ô'Ð'àŒ|×ÒÐ 1Ñ2Ô2ˆØð 	.�D Ô :Ð:Ð:Ý+Ñ-Ô-Ð-ð	.ð 	.Ð:Ð:r   c                 óÖ   — |                       |¦  «        }|                      ||¦  «        }|r3|                      ||¦  «         | j                             d||¬¦  «         di t
          fS )aõ  Validate revocation request and create the response for revocation.
        For example, a client may request the revocation of a refresh token
        with the following request::

            POST /revoke HTTP/1.1
            Host: server.example.com
            Content-Type: application/x-www-form-urlencoded
            Authorization: Basic czZCaGRSa3F0MzpnWDFmQmF0M2JW

            token=45ghiukldjahdnhzdauz&token_type_hint=refresh_token

        :returns: (status_code, body, headers)
        Úafter_revoke_token)r   r   éÈ   )Úauthenticate_endpoint_clientr   Úrevoke_tokenÚserverÚsend_signalr   r   s       r   Úcreate_endpoint_responsez+RevocationEndpoint.create_endpoint_response+   s†   € ð ×2Ò2°7Ñ;Ô;ˆð ×'Ò'¨°Ñ8Ô8ˆð ð 	Ø×Ò˜e WÑ-Ô-Ð-ØŒK×#Ò#Ø$ØØð $ñ ô ð ð
 �BÕ,Ð,Ð,r   c                 ó   — t          ¦   «         ‚)a7  Get the token from database/storage by the given token string.
        Developers should implement this method::

            def query_token(self, token_string, token_type_hint):
                if token_type_hint == 'access_token':
                    return Token.query_by_access_token(token_string)
                if token_type_hint == 'refresh_token':
                    return Token.query_by_refresh_token(token_string)
                return Token.query_by_access_token(token_string) or                     Token.query_by_refresh_token(token_string)
        ©ÚNotImplementedError)r   Útoken_stringr   s      r   r   zRevocationEndpoint.query_tokenJ   s   € õ "Ñ#Ô#Ð#r   c                 ó   — t          ¦   «         ‚)aÚ  Mark token as revoked. Since token MUST be unique, it would be
        dangerous to delete it. Consider this situation:

        1. Jane obtained a token XYZ
        2. Jane revoked (deleted) token XYZ
        3. Bob generated a new token XYZ
        4. Jane can use XYZ to access Bob's resource

        It would be secure to mark a token as revoked::

            def revoke_token(self, token, request):
                hint = request.form.get('token_type_hint')
                if hint == 'access_token':
                    token.access_token_revoked = True
                else:
                    token.access_token_revoked = True
                    token.refresh_token_revoked = True
                token.save()
        r&   )r   r   r   s      r   r!   zRevocationEndpoint.revoke_tokenX   s   € õ( "Ñ#Ô#Ð#r   N)
Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚENDPOINT_NAMEr   r   r$   r   r!   © r   r   r	   r	   	   sp   € € € € € ðð ð !€Mðð ð ð".ð .ð .ð-ð -ð -ð>$ð $ð $ð$ð $ð $ð $ð $r   r	   N)Úauthlib.constsr   Úrfc6749r   r   r   r	   r/   r   r   ú<module>r2      s�   ðØ /Ð /Ð /Ð /Ð /Ð /Ø #Ð #Ð #Ð #Ð #Ð #ðð ð ð ð ð ð ð ðc$ð c$ð c$ð c$ð c$˜ñ c$ô c$ð c$ð c$ð c$r   