§
    iÝ[fê  ã                   óz   — d Z ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddl	m
Z
 dd	lmZ  G d
„ de
¦  «        ZdS )a   
    authlib.oauth2.rfc9068.token_validator
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Implementation of Validating JWT Access Tokens per `Section 4`_.

    .. _`Section 7`: https://www.rfc-editor.org/rfc/rfc9068.html#name-validating-jwt-access-token
é    )Újwt)ÚDecodeError)Ú	JoseError)ÚInsufficientScopeError)ÚInvalidTokenError)ÚBearerTokenValidatoré   )ÚJWTAccessTokenClaimsc                   óH   ‡ — e Zd ZdZˆ fd„Zd„ Zdddefd„Zd„ Z	 dd
„Z	ˆ xZ
S )ÚJWTBearerTokenValidatora"  JWTBearerTokenValidator can protect your resource server endpoints.

    :param issuer: The issuer from which tokens will be accepted.
    :param resource_server: An identifier for the current resource server,
        which must appear in the JWT ``aud`` claim.

    Developers needs to implement the missing methods::

        class MyJWTBearerTokenValidator(JWTBearerTokenValidator):
            def get_jwks(self):
                ...

        require_oauth = ResourceProtector()
        require_oauth.register_token_validator(
            MyJWTBearerTokenValidator(
                issuer='https://authorization-server.example.org',
                resource_server='https://resource-server.example.org',
            )
        )

    You can then protect resources depending on the JWT `scope`, `groups`,
    `roles` or `entitlements` claims::

        @require_oauth(
            scope='profile',
            groups='admins',
            roles='student',
            entitlements='captain',
        )
        def resource_endpoint():
            ...
    c                 óV   •— || _         || _         t          ¦   «         j        |i |¤Ž d S ©N)ÚissuerÚresource_serverÚsuperÚ__init__)Úselfr   r   ÚargsÚkwargsÚ	__class__s        €úZ/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth2/rfc9068/token_validator.pyr   z JWTBearerTokenValidator.__init__4   s4   ø€ ØˆŒØ.ˆÔØ�‰ŒÔ˜$Ð) &Ð)Ð)Ð)Ð)Ð)ó    c                 ó   — t          ¦   «         ‚)az  Return the JWKs that will be used to check the JWT access token signature.
        Developers MUST re-implement this method. Typically the JWKs are statically
        stored in the resource server configuration, or dynamically downloaded and
        cached using :ref:`specs/rfc8414`::

            def get_jwks(self):
                if 'jwks' in cache:
                    return cache.get('jwks')

                server_metadata = get_server_metadata(self.issuer)
                jwks_uri = server_metadata.get('jwks_uri')
                cache['jwks'] = requests.get(jwks_uri).json()
                return cache['jwks']
        )ÚNotImplementedError)r   s    r   Úget_jwksz JWTBearerTokenValidator.get_jwks9   s   € õ "Ñ#Ô#Ð#r   ÚissÚstrÚreturnc                 ó   — || j         k    S r   )r   )r   Úclaimsr   s      r   Úvalidate_issz$JWTBearerTokenValidator.validate_issJ   s   € ð �d”kÒ!Ð!r   c                 ó*  — d| j         dœddid| j        dœddiddiddiddiddiddiddiddiddiddiddidœ}|                      ¦   «         }	 t          j        ||t
          |¬¦  «        S # t          $ r t          | j        | j	        ¬¦  «        ‚w xY w)	Ú T)Ú	essentialÚvalidater$   )r$   ÚvalueF)r   ÚexpÚaudÚsubÚ	client_idÚiatÚjtiÚ	auth_timeÚacrÚamrÚscopeÚgroupsÚrolesÚentitlements)ÚkeyÚ
claims_clsÚclaims_options©ÚrealmÚextra_attributes)
r!   r   r   r   Údecoder
   r   r   r8   r9   )r   Útoken_stringr6   Újwkss       r   Úauthenticate_tokenz*JWTBearerTokenValidator.authenticate_tokenP   s  € ð
 "&°4Ô3DÐEÐEØ Ð&Ø!%°Ô0DÐEÐEØ Ð&Ø% tÐ,Ø Ð&Ø Ð&Ø% uÐ-Ø Ð'Ø Ð'Ø! 5Ð)Ø" EÐ*Ø! 5Ð)Ø(¨%Ð0ð
ð 
ˆð  �}Š}‰Œˆð
	Ý”:ØØÝ/Ø-ð	ñ ô ð øõ ð 	ð 	ð 	Ý#Ø”j°4Ô3Hðñ ô ð ð	øøøs   ÁA, Á,&BNc                 óH  — 	 |                      ¦   «          n.# t          $ r!}t          | j        | j        ¬¦  «        |‚d}~ww xY w|                      |                     dg ¦  «        |¦  «        rt          ¦   «         ‚|                      |                     d¦  «        |¦  «        rt          ¦   «         ‚|                      |                     d¦  «        |¦  «        rt          ¦   «         ‚|                      |                     d¦  «        |¦  «        rt          ¦   «         ‚dS )r#   r7   Nr0   r1   r2   r3   )r%   r   r   r8   r9   Úscope_insufficientÚgetr   )r   ÚtokenÚscopesÚrequestr1   r2   r3   Úexcs           r   Úvalidate_tokenz&JWTBearerTokenValidator.validate_token|   s-  € ð
	Ø�NŠNÑÔÐÐøÝð 	ð 	ð 	Ý#Ø”j°4Ô3Hðñ ô àðøøøøð	øøøð ×"Ò" 5§9¢9¨W°bÑ#9Ô#9¸6ÑBÔBð 	+Ý(Ñ*Ô*Ð*ð ×"Ò" 5§9¢9¨XÑ#6Ô#6¸Ñ?Ô?ð 	&Ý#Ñ%Ô%Ð%à×"Ò" 5§9¢9¨WÑ#5Ô#5°uÑ=Ô=ð 	&Ý#Ñ%Ô%Ð%à×"Ò" 5§9¢9¨^Ñ#<Ô#<¸lÑKÔKð 	&Ý#Ñ%Ô%Ð%ð	&ð 	&s   ‚ —
A¡=½A)NNN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   Úboolr!   r=   rE   Ú__classcell__)r   s   @r   r   r      sŸ   ø€ € € € € ðð ðB*ð *ð *ð *ð *ð
$ð $ð $ð""¨ð "°$ð "ð "ð "ð "ð*ð *ð *ðZ MQð'&ð '&ð '&ð '&ð '&ð '&ð '&ð '&r   r   N)rI   Úauthlib.joser   Úauthlib.jose.errorsr   r   Úauthlib.oauth2.rfc6750.errorsr   r   Ú authlib.oauth2.rfc6750.validatorr   r    r
   r   © r   r   ú<module>rQ      sÎ   ððð ð Ð Ð Ð Ð Ð Ø +Ð +Ð +Ð +Ð +Ð +Ø )Ð )Ð )Ð )Ð )Ð )Ø @Ð @Ð @Ð @Ð @Ð @Ø ;Ð ;Ð ;Ð ;Ð ;Ð ;Ø AÐ AÐ AÐ AÐ AÐ AØ (Ð (Ð (Ð (Ð (Ð (ðQ&ð Q&ð Q&ð Q&ð Q&Ð2ñ Q&ô Q&ð Q&ð Q&ð Q&r   