§
    (ê[f„  ã                   ó”   — d dl Z d dlmZmZ ddlmZmZ ddlmZmZm	Z	m
Z
 ddlmZ  e j        e¦  «        ZdZ G d	„ d
ee¦  «        ZdS )é    N)ÚjwtÚ	JoseErroré   )Ú	BaseGrantÚTokenEndpointMixin)ÚUnauthorizedClientErrorÚInvalidRequestErrorÚInvalidGrantErrorÚInvalidClientErroré   ©Úsign_jwt_bearer_assertionz+urn:ietf:params:oauth:grant-type:jwt-bearerc                   óv   — e Zd ZeZddiddiddidœZe	 	 dd„¦   «         Zd„ Zd„ Z	d„ Z
d	„ Zd
„ Zd„ Zd„ Zd„ ZdS )ÚJWTBearerGrantÚ	essentialT)ÚissÚaudÚexpNc           	      ó(   — t          | ||||||fi |¤ŽS )Nr   )ÚkeyÚissuerÚaudienceÚsubjectÚ	issued_atÚ
expires_atÚclaimsÚkwargss           úU/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth2/rfc7523/jwt_bearer.pyÚsignzJWTBearerGrant.sign   s3   € õ )Ø�˜ 7¨IØ˜ð*ð *à"(ð*ð *ð 	*ó    c                 óø   — 	 t          j        || j        | j        ¬¦  «        }|                     ¦   «          nB# t
          $ r5}t                               d|¦  «         t          |j	        ¬¦  «        ‚d}~ww xY w|S )a#  Extract JWT payload claims from request "assertion", per
        `Section 3.1`_.

        :param assertion: assertion string value in the request
        :return: JWTClaims
        :raise: InvalidGrantError

        .. _`Section 3.1`: https://tools.ietf.org/html/rfc7523#section-3.1
        )Úclaims_optionszAssertion Error: %r©ÚdescriptionN)
r   ÚdecodeÚresolve_public_keyÚCLAIMS_OPTIONSÚvalidater   ÚlogÚdebugr
   r$   )ÚselfÚ	assertionr   Úes       r   Úprocess_assertion_claimsz'JWTBearerGrant.process_assertion_claims"   sŽ   € ð	?Ý”ZØ˜4Ô2Ø#Ô2ð4ñ 4ô 4ˆFð �OŠOÑÔÐÐøÝð 	?ð 	?ð 	?Ý�IŠIÐ+¨QÑ/Ô/Ð/Ý#°´Ð>Ñ>Ô>Ð>øøøøð	?øøøð ˆs   ‚58 ¸
A7Á0A2Á2A7c                 óf   — |                       |d         ¦  «        }|                      |||¦  «        S )Nr   )Úresolve_issuer_clientÚresolve_client_key)r+   ÚheadersÚpayloadÚclients       r   r&   z!JWTBearerGrant.resolve_public_key6   s1   € Ø×+Ò+¨G°E¬NÑ;Ô;ˆØ×&Ò& v¨w¸Ñ@Ô@Ð@r    c                 ó¨  — | j         j                             d¦  «        }|st          d¦  «        ‚|                      |¦  «        }|                      |d         ¦  «        }t                               d|¦  «         |                     | j	        ¦  «        st          ¦   «         ‚|| j         _        |                      ¦   «          |                     d¦  «        }|rw|                      |¦  «        }|st          d¬¦  «        ‚t                               d||¦  «         |                      ||¦  «        st!          d	¬¦  «        ‚|| j         _        d
S d
S )añ  The client makes a request to the token endpoint by sending the
        following parameters using the "application/x-www-form-urlencoded"
        format per `Section 2.1`_:

        grant_type
             REQUIRED.  Value MUST be set to
             "urn:ietf:params:oauth:grant-type:jwt-bearer".

        assertion
             REQUIRED.  Value MUST contain a single JWT.

        scope
            OPTIONAL.

        The following example demonstrates an access token request with a JWT
        as an authorization grant:

        .. code-block:: http

            POST /token.oauth2 HTTP/1.1
            Host: as.example.com
            Content-Type: application/x-www-form-urlencoded

            grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer
            &assertion=eyJhbGciOiJFUzI1NiIsImtpZCI6IjE2In0.
            eyJpc3Mi[...omitted for brevity...].
            J9l-ZhwP[...omitted for brevity...]

        .. _`Section 2.1`: https://tools.ietf.org/html/rfc7523#section-2.1
        r,   zMissing "assertion" in requestr   zValidate token request of %sÚsubz Invalid "sub" value in assertionr#   z'Check client(%s) permission to User(%s)z,Client has no permission to access user dataN)ÚrequestÚformÚgetr	   r.   r0   r)   r*   Úcheck_grant_typeÚ
GRANT_TYPEr   r4   Úvalidate_requested_scopeÚauthenticate_userr
   Úhas_granted_permissionr   Úuser)r+   r,   r   r4   r   r?   s         r   Úvalidate_token_requestz%JWTBearerGrant.validate_token_request:   sb  € ð> ”LÔ%×)Ò)¨+Ñ6Ô6ˆ	Øð 	HÝ%Ð&FÑGÔGÐGà×.Ò.¨yÑ9Ô9ˆØ×+Ò+¨F°5¬MÑ:Ô:ˆÝ�	Š	Ð0°&Ñ9Ô9Ð9à×&Ò& t¤Ñ7Ô7ð 	,Ý)Ñ+Ô+Ð+à$ˆŒÔØ×%Ò%Ñ'Ô'Ð'à—*’*˜UÑ#Ô#ˆØð 		%Ø×)Ò)¨'Ñ2Ô2ˆDØð XÝ'Ð4VÐWÑWÔWÐWå�IŠIÐ?ÀÈÑNÔNÐNØ×.Ò.¨v°tÑ<Ô<ð PÝ(Ø NðPñ Pô Pð Pà $ˆDŒLÔÐÐð		%ð 		%r    c                 óä   — |                       | j        j        | j        j        d¬¦  «        }t                               d|| j        j        ¦  «         |                      |¦  «         d|| j        fS )zZIf valid and authorized, the authorization server issues an access
        token.
        F)Úscoper?   Úinclude_refresh_tokenzIssue token %r to %réÈ   )	Úgenerate_tokenr7   rB   r?   r)   r*   r4   Ú
save_tokenÚTOKEN_RESPONSE_HEADER)r+   Útokens     r   Úcreate_token_responsez$JWTBearerGrant.create_token_responses   sq   € ð ×#Ò#Ø”,Ô$Ø”Ô"Ø"'ð $ñ 
ô 
ˆõ
 	�	Š	Ð(¨%°´Ô1DÑEÔEÐEØ�Š˜ÑÔÐØ�E˜4Ô5Ð5Ð5r    c                 ó   — t          ¦   «         ‚)a1  Fetch client via "iss" in assertion claims. Developers MUST
        implement this method in subclass, e.g.::

            def resolve_issuer_client(self, issuer):
                return Client.query_by_iss(issuer)

        :param issuer: "iss" value in assertion
        :return: Client instance
        ©ÚNotImplementedError)r+   r   s     r   r0   z$JWTBearerGrant.resolve_issuer_client€   ó   € õ "Ñ#Ô#Ð#r    c                 ó   — t          ¦   «         ‚)au  Resolve client key to decode assertion data. Developers MUST
        implement this method in subclass. For instance, there is a
        "jwks" column on client table, e.g.::

            def resolve_client_key(self, client, headers, payload):
                # from authlib.jose import JsonWebKey

                key_set = JsonWebKey.import_key_set(client.jwks)
                return key_set.find_by_kid(headers['kid'])

        :param client: instance of OAuth client model
        :param headers: headers part of the JWT
        :param payload: payload part of the JWT
        :return: ``authlib.jose.Key`` instance
        rK   )r+   r4   r2   r3   s       r   r1   z!JWTBearerGrant.resolve_client_keyŒ   s   € õ  "Ñ#Ô#Ð#r    c                 ó   — t          ¦   «         ‚)a%  Authenticate user with the given assertion claims. Developers MUST
        implement it in subclass, e.g.::

            def authenticate_user(self, subject):
                return User.get_by_sub(subject)

        :param subject: "sub" value in claims
        :return: User instance
        rK   )r+   r   s     r   r=   z JWTBearerGrant.authenticate_userž   rM   r    c                 ó   — t          ¦   «         ‚)a¶  Check if the client has permission to access the given user's resource.
        Developers MUST implement it in subclass, e.g.::

            def has_granted_permission(self, client, user):
                permission = ClientUserGrant.query(client=client, user=user)
                return permission.granted

        :param client: instance of OAuth client model
        :param user: instance of User model
        :return: bool
        rK   )r+   r4   r?   s      r   r>   z%JWTBearerGrant.has_granted_permissionª   s   € õ "Ñ#Ô#Ð#r    )NNNN)Ú__name__Ú
__module__Ú__qualname__ÚJWT_BEARER_GRANT_TYPEr;   r'   Ústaticmethodr   r.   r&   r@   rI   r0   r1   r=   r>   © r    r   r   r      sá   € € € € € Ø&€Jð
 ˜TÐ"Ø˜TÐ"Ø˜TÐ"ðð €Nð Ø,0Ø59ð*ð *ð *ñ „\ð*ðð ð ð(Að Að Að7%ð 7%ð 7%ðr6ð 6ð 6ð
$ð 
$ð 
$ð$ð $ð $ð$
$ð 
$ð 
$ð$ð $ð $ð $ð $r    r   )ÚloggingÚauthlib.joser   r   Úrfc6749r   r   r   r	   r
   r   r,   r   Ú	getLoggerrQ   r)   rT   r   rV   r    r   ú<module>r[      sç   ðØ €€€Ø 'Ð 'Ð 'Ð 'Ð 'Ð 'Ð 'Ð 'Ø 3Ð 3Ð 3Ð 3Ð 3Ð 3Ð 3Ð 3ðð ð ð ð ð ð ð ð ð ð ð ð 1Ð 0Ð 0Ð 0Ð 0Ð 0à€gÔ˜Ñ!Ô!€ØEÐ ðf$ð f$ð f$ð f$ð f$�YÐ 2ñ f$ô f$ð f$ð f$ð f$r    