§
    (ê[f+7  ã                   ó¸   — d Z ddlZddlZddlZddlmZ ddlmZmZ ddl	m
Z
mZ dZdZd	Zd
ZdZdZdd„Zdd„Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ ZdS )zå
    authlib.oauth1.rfc5849.signature
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    This module represents a direct implementation of `section 3.4`_ of the spec.

    .. _`section 3.4`: https://tools.ietf.org/html/rfc5849#section-3.4
é    N)Úurlparse)Ú
to_unicodeÚto_bytesé   )ÚescapeÚunescapez	HMAC-SHA1zRSA-SHA1Ú	PLAINTEXTÚHEADERÚQUERYÚBODYc                 óv  — t          ||¦  «        }g }|D ]E\  }}|dv rŒ
|                     d¦  «        rt          |¦  «        }|                     ||f¦  «         ŒFt	          |¦  «        }d                     t          |                      ¦   «         ¦  «        t          |¦  «        t          |¦  «        g¦  «        S )aX  Generate signature base string from request, per `Section 3.4.1`_.

    For example, the HTTP request::

        POST /request?b5=%3D%253D&a3=a&c%40=&a2=r%20b HTTP/1.1
        Host: example.com
        Content-Type: application/x-www-form-urlencoded
        Authorization: OAuth realm="Example",
            oauth_consumer_key="9djdj82h48djs9d2",
            oauth_token="kkk9d7dh3k39sjv7",
            oauth_signature_method="HMAC-SHA1",
            oauth_timestamp="137131201",
            oauth_nonce="7d8f3e4a",
            oauth_signature="bYT5CMsGcbgUdFHObYMEfcx6bsw%3D"

        c2&a3=2+q

    is represented by the following signature base string (line breaks
    are for display purposes only)::

        POST&http%3A%2F%2Fexample.com%2Frequest&a2%3Dr%2520b%26a3%3D2%2520q
        %26a3%3Da%26b5%3D%253D%25253D%26c%2540%3D%26c2%3D%26oauth_consumer_
        key%3D9djdj82h48djs9d2%26oauth_nonce%3D7d8f3e4a%26oauth_signature_m
        ethod%3DHMAC-SHA1%26oauth_timestamp%3D137131201%26oauth_token%3Dkkk
        9d7dh3k39sjv7

    .. _`Section 3.4.1`: https://tools.ietf.org/html/rfc5849#section-3.4.1
    )Úoauth_signatureÚrealmÚoauth_ú&)Únormalize_base_string_uriÚ
startswithr   ÚappendÚnormalize_parametersÚjoinr   Úupper)	ÚmethodÚuriÚparamsÚhostÚbase_string_uriÚunescaped_paramsÚkÚvÚnormalized_paramss	            úT/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth1/rfc5849/signature.pyÚconstruct_base_stringr"      sÑ   € õ> 0°°TÑ:Ô:€Oð ÐØð (ð (‰ˆˆ1àÐ,Ð,Ð,Øð �<Š<˜Ñ!Ô!ð 	Ý˜‘”ˆAØ×Ò  A Ñ'Ô'Ð'Ð'õ -Ð-=Ñ>Ô>Ðð �8Š8Ýˆv�|Š|‰~Œ~ÑÔÝˆÑÔÝÐ Ñ!Ô!ðñ ô ð ó    c                 ó‚  — t          | ¦  «        } t          j        | ¦  «        \  }}}}}}|r|st          d¦  «        ‚|sd}|                     ¦   «         }|                     ¦   «         }|�|                     ¦   «         }d}d|v r!|                     dd¦  «        \  }}	||	f|v r|}t          j        ||||ddf¦  «        S )a7  Normalize Base String URI per `Section 3.4.1.2`_.

    For example, the HTTP request::

        GET /r%20v/X?id=123 HTTP/1.1
        Host: EXAMPLE.COM:80

    is represented by the base string URI: "http://example.com/r%20v/X".

    In another example, the HTTPS request::

        GET /?q=1 HTTP/1.1
        Host: www.example.net:8080

    is represented by the base string URI: "https://www.example.net:8080/".

    .. _`Section 3.4.1.2`: https://tools.ietf.org/html/rfc5849#section-3.4.1.2

    The host argument overrides the netloc part of the uri argument.
    z$uri must include a scheme and netlocú/N))ÚhttpÚ80)ÚhttpsÚ443ú:r   Ú )r   r   Ú
ValueErrorÚlowerÚsplitÚ
urlunparse)
r   r   ÚschemeÚnetlocÚpathr   ÚqueryÚfragmentÚdefault_portsÚports
             r!   r   r   Q   sé   € õ* �S‰/Œ/€CÝ4<Ô4EÀcÑ4JÔ4JÑ1€FˆF�D˜& %¨ð ð A˜ð AÝÐ?Ñ@Ô@Ð@ð ð Øˆð �\Š\‰^Œ^€FØ�\Š\‰^Œ^€Fð ÐØ—’‘”ˆð€Mð ˆf€}€}Ø—\’\ # qÑ)Ô)‰
ˆˆdØ�Dˆ>˜]Ð*Ð*ØˆFåÔ ¨°°f¸bÀ"ÐEÑFÔFÐFr#   c                 ó„   — d„ | D ¦   «         }|                      ¦   «          d„ |D ¦   «         }d                     |¦  «        S )a×
  Normalize parameters per `Section 3.4.1.3.2`_.

    For example, the list of parameters from the previous section would
    be normalized as follows:

    Encoded::

    +------------------------+------------------+
    |          Name          |       Value      |
    +------------------------+------------------+
    |           b5           |     %3D%253D     |
    |           a3           |         a        |
    |          c%40          |                  |
    |           a2           |       r%20b      |
    |   oauth_consumer_key   | 9djdj82h48djs9d2 |
    |       oauth_token      | kkk9d7dh3k39sjv7 |
    | oauth_signature_method |     HMAC-SHA1    |
    |     oauth_timestamp    |     137131201    |
    |       oauth_nonce      |     7d8f3e4a     |
    |           c2           |                  |
    |           a3           |       2%20q      |
    +------------------------+------------------+

    Sorted::

    +------------------------+------------------+
    |          Name          |       Value      |
    +------------------------+------------------+
    |           a2           |       r%20b      |
    |           a3           |       2%20q      |
    |           a3           |         a        |
    |           b5           |     %3D%253D     |
    |          c%40          |                  |
    |           c2           |                  |
    |   oauth_consumer_key   | 9djdj82h48djs9d2 |
    |       oauth_nonce      |     7d8f3e4a     |
    | oauth_signature_method |     HMAC-SHA1    |
    |     oauth_timestamp    |     137131201    |
    |       oauth_token      | kkk9d7dh3k39sjv7 |
    +------------------------+------------------+

    Concatenated Pairs::

    +-------------------------------------+
    |              Name=Value             |
    +-------------------------------------+
    |               a2=r%20b              |
    |               a3=2%20q              |
    |                 a3=a                |
    |             b5=%3D%253D             |
    |                c%40=                |
    |                 c2=                 |
    | oauth_consumer_key=9djdj82h48djs9d2 |
    |         oauth_nonce=7d8f3e4a        |
    |   oauth_signature_method=HMAC-SHA1  |
    |      oauth_timestamp=137131201      |
    |     oauth_token=kkk9d7dh3k39sjv7    |
    +-------------------------------------+

    and concatenated together into a single string (line breaks are for
    display purposes only)::

        a2=r%20b&a3=2%20q&a3=a&b5=%3D%253D&c%40=&c2=&oauth_consumer_key=9dj
        dj82h48djs9d2&oauth_nonce=7d8f3e4a&oauth_signature_method=HMAC-SHA1
        &oauth_timestamp=137131201&oauth_token=kkk9d7dh3k39sjv7

    .. _`Section 3.4.1.3.2`: https://tools.ietf.org/html/rfc5849#section-3.4.1.3.2
    c                 óP   — g | ]#\  }}t          |¦  «        t          |¦  «        f‘Œ$S © ©r   ©Ú.0r   r   s      r!   ú
<listcomp>z(normalize_parameters.<locals>.<listcomp>â   s-   € Ð<Ð<Ð<©T¨Q°•6˜!‘9”9�f Q™iœiÐ(Ð<Ð<Ð<r#   c                 ó"   — g | ]\  }}|› d |› �‘ŒS )ú=r9   r;   s      r!   r=   z(normalize_parameters.<locals>.<listcomp>ì   s&   € Ð9Ð9Ð9¡d a¨˜!�z�z˜a�z�zÐ9Ð9Ð9r#   r   )Úsortr   )r   Ú
key_valuesÚparameter_partss      r!   r   r   ˜   sS   € ðT =Ð<°VÐ<Ñ<Ô<€Jð
 ‡O‚OÑÔÐð
 :Ð9¨jÐ9Ñ9Ô9€Oð
 �8Š8�OÑ$Ô$Ð$r#   c                 óz   — | j                              dd¦  «        }t          | j        | j        | j        |¦  «        S )z,Generate signature base string from request.ÚHostN)ÚheadersÚgetr"   r   r   r   )Úrequestr   s     r!   Úgenerate_signature_base_stringrH   ô   s:   € àŒ?×Ò˜v tÑ,Ô,€DÝ ØŒ˜œ W¤^°Tñ;ô ;ð ;r#   c                 óH  — | }t          |pd¦  «        }|dz  }|t          |pd¦  «        z  }t          j        t          |¦  «        t          |¦  «        t          j        ¦  «        }t          j        |                     ¦   «         ¦  «        dd…         }t          |¦  «        S )aZ  Generate signature via HMAC-SHA1 method, per `Section 3.4.2`_.

    The "HMAC-SHA1" signature method uses the HMAC-SHA1 signature
    algorithm as defined in `RFC2104`_::

        digest = HMAC-SHA1 (key, text)

    .. _`RFC2104`: https://tools.ietf.org/html/rfc2104
    .. _`Section 3.4.2`: https://tools.ietf.org/html/rfc5849#section-3.4.2
    r+   r   Néÿÿÿÿ)
r   ÚhmacÚnewr   ÚhashlibÚsha1ÚbinasciiÚ
b2a_base64Údigestr   )Úbase_stringÚclient_secretÚtoken_secretÚtextÚkeyÚ	signatureÚsigs          r!   Úhmac_sha1_signaturerY   û   s•   € ð$ €Dõ �Ð$ "Ñ
%Ô
%€Cð ˆ3�J€Cð
 �6�,Ð$ "Ñ%Ô%Ñ%€Cå”� #™œ­°©¬½¼ÑEÔE€Iõ Ô
˜i×.Ò.Ñ0Ô0Ñ
1Ô
1°#°2°#Ô
6€CÝ�c‰?Œ?Ðr#   c                 ó´   — ddl m} t          | ¦  «        }  |t          | ¦  «        |¦  «        }t          j        |¦  «        dd…         }t          |¦  «        S )ar  Generate signature via RSA-SHA1 method, per `Section 3.4.3`_.

    The "RSA-SHA1" signature method uses the RSASSA-PKCS1-v1_5 signature
    algorithm as defined in `RFC3447, Section 8.2`_ (also known as
    PKCS#1), using SHA-1 as the hash function for EMSA-PKCS1-v1_5.  To
    use this method, the client MUST have established client credentials
    with the server that included its RSA public key (in a manner that is
    beyond the scope of this specification).

    .. _`Section 3.4.3`: https://tools.ietf.org/html/rfc5849#section-3.4.3
    .. _`RFC3447, Section 8.2`: https://tools.ietf.org/html/rfc3447#section-8.2
    r   )Ú	sign_sha1NrJ   )Úrsar[   r   rO   rP   r   )rR   Úrsa_private_keyr[   ÚsrX   s        r!   Úrsa_sha1_signaturer_   )  sa   € ð ÐÐÐÐÐÝ˜;Ñ'Ô'€KØˆ	•(˜;Ñ'Ô'¨Ñ9Ô9€AÝ
Ô
˜aÑ
 Ô
   " Ô
%€CÝ�c‰?Œ?Ðr#   c                 óZ   — t          | pd¦  «        }|dz  }|t          |pd¦  «        z  }|S )aÊ  Generate signature via PLAINTEXT method, per `Section 3.4.4`_.

    The "PLAINTEXT" method does not employ a signature algorithm.  It
    MUST be used with a transport-layer mechanism such as TLS or SSL (or
    sent over a secure channel with equivalent protections).  It does not
    utilize the signature base string or the "oauth_timestamp" and
    "oauth_nonce" parameters.

    .. _`Section 3.4.4`: https://tools.ietf.org/html/rfc5849#section-3.4.4
    r+   r   r:   )rS   rT   rW   s      r!   Úplaintext_signaturera   =  sA   € õ$ �}Ð*¨Ñ+Ô+€Ið �Ñ€Ið
 •˜Ð*¨Ñ+Ô+Ñ+€IàÐr#   c                 óV   — t          |¦  «        }t          || j        | j        ¦  «        S )zSign a HMAC-SHA1 signature.)rH   rY   rS   rT   ©ÚclientrG   rR   s      r!   Úsign_hmac_sha1re   ]  s1   € å0°Ñ9Ô9€KÝØ�VÔ)¨6Ô+>ñ@ô @ð @r#   c                 óJ   — t          |¦  «        }t          || j        ¦  «        S )z4Sign a RSASSA-PKCS #1 v1.5 base64 encoded signature.)rH   r_   Úrsa_keyrc   s      r!   Úsign_rsa_sha1rh   d  s!   € å0°Ñ9Ô9€KÝ˜k¨6¬>Ñ:Ô:Ð:r#   c                 ó6   — t          | j        | j        ¦  «        S )zSign a PLAINTEXT signature.)ra   rS   rT   )rd   rG   s     r!   Úsign_plaintextrj   j  s   € å˜vÔ3°VÔ5HÑIÔIÐIr#   c                 óŠ   — t          | ¦  «        }t          || j        | j        ¦  «        }t	          j        || j        ¦  «        S )zVerify a HMAC-SHA1 signature.)rH   rY   rS   rT   rK   Úcompare_digestrW   )rG   rR   rX   s      r!   Úverify_hmac_sha1rm   o  sC   € å0°Ñ9Ô9€KÝ
Ø�WÔ*¨GÔ,@ñBô B€CåÔ˜s GÔ$5Ñ6Ô6Ð6r#   c                 ó¶   — ddl m} t          | ¦  «        }t          j        t          | j        ¦  «        ¦  «        } ||t          |¦  «        | j        ¦  «        S )z6Verify a RSASSA-PKCS #1 v1.5 base64 encoded signature.r   )Úverify_sha1)r\   ro   rH   rO   Ú
a2b_base64r   rW   Úrsa_public_key)rG   ro   rR   rX   s       r!   Úverify_rsa_sha1rr   w  s[   € à Ð Ð Ð Ð Ð Ý0°Ñ9Ô9€KÝ
Ô
�h wÔ'8Ñ9Ô9Ñ
:Ô
:€CØˆ;�s�H [Ñ1Ô1°7Ô3IÑJÔJÐJr#   c                 ój   — t          | j        | j        ¦  «        }t          j        || j        ¦  «        S )zVerify a PLAINTEXT signature.)ra   rS   rT   rK   rl   rW   )rG   rX   s     r!   Úverify_plaintextrt     s-   € å
˜gÔ3°WÔ5IÑ
JÔ
J€CÝÔ˜s GÔ$5Ñ6Ô6Ð6r#   )N)Ú__doc__rO   rM   rK   Úauthlib.common.urlsr   Úauthlib.common.encodingr   r   Úutilr   r   ÚSIGNATURE_HMAC_SHA1ÚSIGNATURE_RSA_SHA1ÚSIGNATURE_PLAINTEXTÚSIGNATURE_TYPE_HEADERÚSIGNATURE_TYPE_QUERYÚSIGNATURE_TYPE_BODYr"   r   r   rH   rY   r_   ra   re   rh   rj   rm   rr   rt   r9   r#   r!   ú<module>r      s‚  ððð ð €€€Ø €€€Ø €€€Ø (Ð (Ð (Ð (Ð (Ð (Ø 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ø "Ð "Ð "Ð "Ð "Ð "Ð "Ð "à!Ð ØÐ Ø!Ð à Ð ØÐ ØÐ ð5ð 5ð 5ð 5ðpDGð DGð DGð DGðNY%ð Y%ð Y%ðx;ð ;ð ;ð+ð +ð +ð\ð ð ð(ð ð ð@@ð @ð @ð;ð ;ð ;ðJð Jð Jð
7ð 7ð 7ðKð Kð Kð7ð 7ð 7ð 7ð 7r#   