§
    iÝ[f  ã                   óº   — d dl Z d dlmZ d dlmZmZ d dlmZ d dlm	Z	 d dl
mZmZ d dlmZ dd	lmZ dd
lmZ ddlmZ  G d„ de¦  «        Zd„ Z e	e¦  «        ZdS )é    N)Úcontextmanager)ÚgÚjson)Úrequest)Ú
LocalProxy)ÚOAuth2ErrorÚResourceProtector)ÚMissingAuthorizationErroré   )ÚFlaskJsonRequest)Útoken_authenticated)Úraise_http_exceptionc                   ó@   — e Zd ZdZd„ Zdd„Zedd„¦   «         Zd	d„ZdS )
r	   ax  A protecting method for resource servers. Creating a ``require_oauth``
    decorator easily with ResourceProtector::

        from authlib.integrations.flask_oauth2 import ResourceProtector

        require_oauth = ResourceProtector()

        # add bearer token validator
        from authlib.oauth2.rfc6750 import BearerTokenValidator
        from project.models import Token

        class MyBearerTokenValidator(BearerTokenValidator):
            def authenticate_token(self, token_string):
                return Token.query.filter_by(access_token=token_string).first()

        require_oauth.register_token_validator(MyBearerTokenValidator())

        # protect resource with require_oauth

        @app.route('/user')
        @require_oauth(['profile'])
        def user_profile():
            user = User.get(current_token.user_id)
            return jsonify(user.to_dict())

    c                 óÄ   — |j         }t          j        t          |                     ¦   «         ¦  «        ¦  «        }|                     ¦   «         }t          |||¦  «         dS )z¿Raise HTTPException for OAuth2Error. Developers can re-implement
        this method to customize the error response.

        :param error: OAuth2Error
        :raise: HTTPException
        N)Ústatus_coder   ÚdumpsÚdictÚget_bodyÚget_headersr   )ÚselfÚerrorÚstatusÚbodyÚheaderss        úh/var/www/piapp/venv/lib/python3.11/site-packages/authlib/integrations/flask_oauth2/resource_protector.pyÚraise_error_responsez&ResourceProtector.raise_error_response-   sV   € ð Ô"ˆÝŒz�$˜uŸ~š~Ñ/Ô/Ñ0Ô0Ñ1Ô1ˆØ×#Ò#Ñ%Ô%ˆÝ˜V T¨7Ñ3Ô3Ð3Ð3Ð3ó    Nc                 óò   — t          t          ¦  «        }||d<   |D ])}t          ||         t          ¦  «        r||         g||<   Œ* | j        dd|i|¤Ž}t          j        | |¬¦  «         |t          _        |S )z“A method to acquire current valid token with the given scope.

        :param scopes: a list of scope values
        :return: token object
        Úscopesr   )Útoken© )	r   Ú_reqÚ
isinstanceÚstrÚvalidate_requestr   Úsendr   Úauthlib_server_oauth2_token)r   r   Úkwargsr   Úclaimr    s         r   Úacquire_tokenzResourceProtector.acquire_token9   s�   € õ #¥4Ñ(Ô(ˆà!ˆˆxÑØð 	0ð 	0ˆEÝ˜& œ-­Ñ-Ô-ð 0Ø!'¨¤ ��u‘øØ%�Ô%Ð@Ð@¨gÐ@¸Ð@Ð@ˆÝÔ  ¨UÐ3Ñ3Ô3Ð3Ø(-�Ô%Øˆr   c              #   ó”   K  — 	 |                       |¦  «        V — dS # t          $ r }|                      |¦  «         Y d}~dS d}~ww xY w)ae  The with statement of ``require_oauth``. Instead of using a
        decorator, you can use a with statement instead::

            @app.route('/api/user')
            def user_api():
                with require_oauth.acquire('profile') as token:
                    user = User.get(token.user_id)
                    return jsonify(user.to_dict())
        N)r*   r   r   )r   r   r   s      r   ÚacquirezResourceProtector.acquireJ   sp   è è € ð	-Ø×$Ò$ VÑ,Ô,Ð,Ð,Ð,Ð,Ð,øÝð 	-ð 	-ð 	-Ø×%Ò% eÑ,Ô,Ð,Ð,Ð,Ð,Ð,Ð,Ð,øøøøð	-øøøs   „ �
A§AÁAFc                 ó(   ‡ ‡‡— |Š|‰d<   ˆˆˆ fd„}|S )Nr   c                 óN   •‡ — t          j        ‰ ¦  «        ˆˆ ˆˆfd„¦   «         }|S )Nc                  óö   •— 	  ‰j         di ‰¤Ž nb# t          $ r.}‰r ‰| i |¤ŽcY d }~S ‰                     |¦  «         Y d }~n/d }~wt          $ r}‰                     |¦  «         Y d }~nd }~ww xY w ‰| i |¤ŽS )Nr!   )r*   r
   r   r   )Úargsr(   r   ÚclaimsÚfÚoptionalr   s      €€€€r   Ú	decoratedz>ResourceProtector.__call__.<locals>.wrapper.<locals>.decorated_   sà   ø€ ð5Ø&�DÔ&Ð0Ð0¨Ð0Ð0Ð0Ð0øÝ0ð 5ð 5ð 5Øð 2Ø ˜q $Ð1¨&Ð1Ð1Ð1Ð1Ð1Ð1Ð1Ð1Ø×-Ò-¨eÑ4Ô4Ð4Ð4Ð4Ð4Ð4Ð4øøøøÝ"ð 5ð 5ð 5Ø×-Ò-¨eÑ4Ô4Ð4Ð4Ð4Ð4Ð4Ð4øøøøð5øøøà�q˜$Ð) &Ð)Ð)Ð)s*   ƒ ‘
A0›	A¤A0ªAÁA0ÁA+Á+A0)Ú	functoolsÚwraps)r2   r4   r1   r3   r   s   ` €€€r   Úwrapperz+ResourceProtector.__call__.<locals>.wrapper^   sI   øø€ ÝŒ_˜QÑÔð	*ð 	*ð 	*ð 	*ð 	*ð 	*ð 	*ñ  Ôð	*ð Ðr   r!   )r   r   r3   r(   r7   r1   s   ` `  @r   Ú__call__zResourceProtector.__call__Z   s>   øøø€ Øˆà!ˆˆxÑð	ð 	ð 	ð 	ð 	ð 	ð 	ð ˆr   )N)NF)	Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r*   r   r,   r8   r!   r   r   r	   r	      su   € € € € € ðð ð4
4ð 
4ð 
4ðð ð ð ð" ð-ð -ð -ñ „^ð-ðð ð ð ð ð r   r	   c                  ó*   — t          j        d¦  «        S )Nr'   )r   Úgetr!   r   r   Ú_get_current_tokenr?   n   s   € ÝŒ5Ð.Ñ/Ô/Ð/r   )r5   Ú
contextlibr   Úflaskr   r   r   r"   Úwerkzeug.localr   Úauthlib.oauth2r   r	   Ú_ResourceProtectorÚauthlib.oauth2.rfc6749r
   Úrequestsr   Úsignalsr   Úerrorsr   r?   Úcurrent_tokenr!   r   r   ú<module>rJ      s6  ðØ Ð Ð Ð Ø %Ð %Ð %Ð %Ð %Ð %Ø Ð Ð Ð Ð Ð Ð Ð Ø !Ð !Ð !Ð !Ð !Ð !Ø %Ð %Ð %Ð %Ð %Ð %ðð ð ð ð ð ð ð ðð ð ð ð ð ð 'Ð &Ð &Ð &Ð &Ð &Ø (Ð (Ð (Ð (Ð (Ð (Ø (Ð (Ð (Ð (Ð (Ð (ðYð Yð Yð Yð YÐ*ñ Yô Yð Yðx0ð 0ð 0ð �
Ð-Ñ.Ô.€€€r   