§
    (ê[fÚD  ã                   ó”   — d dl mZ d dlmZ ddlmZmZmZmZ ddl	m
Z
 ddlmZ ddlmZmZ ddlmZ d	d
dœZ G d„ d¦  «        Zd„ ZdS )é    )Úgenerate_token)Ú
url_decodeé   )Úprepare_grant_uriÚprepare_token_requestÚ!parse_authorization_code_responseÚparse_implicit_response)Úprepare_revoke_token_request)Úcreate_s256_code_challenge)Ú	TokenAuthÚ
ClientAuth)ÚOAuth2Errorzapplication/jsonz/application/x-www-form-urlencoded;charset=UTF-8)ÚAcceptzContent-Typec                   ó  — e Zd ZdZeZeZeZ	dZ
g Z	 	 	 	 	 dd„Zd„ Zd„ Zed„ ¦   «         Zej        d	„ ¦   «         Zdd
„Z	 	 dd„Zdd„Z	 	 dd„Zd„ Z	 	 d d„Z	 	 d d„Zd„ Zd„ Z	 	 d!d„Z	 	 dd„Z	 	 d d„Zd„ Zd„ Zd"d„Z dS )#ÚOAuth2ClientaZ  Construct a new OAuth 2 protocol client.

    :param session: Requests session object to communicate with
                    authorization server.
    :param client_id: Client ID, which you get from client registration.
    :param client_secret: Client Secret, which you get from registration.
    :param token_endpoint_auth_method: client authentication method for
        token endpoint.
    :param revocation_endpoint_auth_method: client authentication method for
        revocation endpoint.
    :param scope: Scope that you needed to access user resources.
    :param state: Shared secret to prevent CSRF attack.
    :param redirect_uri: Redirect URI you registered as callback.
    :param code_challenge_method: PKCE method name, only S256 is supported.
    :param token: A dict of token attributes such as ``access_token``,
        ``token_type`` and ``expires_at``.
    :param token_placement: The place to put token in HTTP request. Available
        values: "header", "body", "uri".
    :param update_token: A function for you to update token. It accept a
        :class:`OAuth2Token` as parameter.
    )Úresponse_modeÚnonceÚpromptÚ
login_hintNÚheaderc                 óê  — || _         || _        || _        || _        |€|rd}nd}|| _        |€|rd}nd}|| _        || _        || _        |	| _        |  	                    |
|| ¦  «        | _
        || _        |                     dd ¦  «        }|rt          d¦  «        ‚|| _        t          ¦   «         t          ¦   «         t          ¦   «         t          ¦   «         t          ¦   «         dœ| _        i | _        d S )NÚclient_secret_basicÚnoneÚtoken_updaterz<update token has been redesigned, checkout the documentation)Úaccess_token_responseÚrefresh_token_requestÚrefresh_token_responseÚrevoke_token_requestÚintrospect_token_request)ÚsessionÚ	client_idÚclient_secretÚstateÚtoken_endpoint_auth_methodÚrevocation_endpoint_auth_methodÚscopeÚredirect_uriÚcode_challenge_methodÚtoken_auth_classÚ
token_authÚupdate_tokenÚpopÚ
ValueErrorÚmetadataÚsetÚcompliance_hookÚ_auth_methods)Úselfr    r!   r"   r$   r%   r&   r#   r'   r(   ÚtokenÚtoken_placementr+   r.   r   s                  úI/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth2/client.pyÚ__init__zOAuth2Client.__init__3   s  € ð ˆŒØ"ˆŒØ*ˆÔØˆŒ
à%Ð-Øð 4Ø-BÐ*Ð*à-3Ð*à*DˆÔ'à*Ð2Øð 9Ø2GÐ/Ð/à28Ð/à/NˆÔ,àˆŒ
Ø(ˆÔØ%:ˆÔ"à×/Ò/°°ÈÑMÔMˆŒØ(ˆÔà Ÿš _°dÑ;Ô;ˆØð 	]ÝÐ[Ñ\Ô\Ð\à ˆŒõ &)¡U¤UÝ%(¡U¤UÝ&)¡e¤eÝ$'¡E¤EÝ(+©¬ð 
ð  
ˆÔð  ˆÔÐÐó    c                 ó~   — t          |t          ¦  «        r|d         | j        |d         <   dS || j        |j        <   dS )zmExtend client authenticate for token endpoint.

        :param auth: an instance to sign the request
        r   r   N)Ú
isinstanceÚtupler1   Úname)r2   Úauths     r5   Úregister_client_auth_methodz(OAuth2Client.register_client_auth_methodd   sF   € õ
 �d�EÑ"Ô"ð 	1Ø*.¨q¬'ˆDÔ˜t AœwÑ'Ð'Ð'à,0ˆDÔ˜tœyÑ)Ð)Ð)r7   c                 óœ   — t          |t          ¦  «        r|| j        v r| j        |         }|                      | j        | j        |¬¦  «        S )N)r!   r"   Úauth_method)r9   Ústrr1   Úclient_auth_classr!   r"   )r2   r?   s     r5   Úclient_authzOAuth2Client.client_authn   sY   € Ý�k¥3Ñ'Ô'ð 	:¨K¸4Ô;MÐ,MÐ,MØÔ,¨[Ô9ˆKØ×%Ò%Ø”nØÔ,Ø#ð &ñ 
ô 
ð 	
r7   c                 ó   — | j         j        S ©N)r*   r3   )r2   s    r5   r3   zOAuth2Client.tokenw   s   € àŒÔ$Ð$r7   c                 ó:   — | j                              |¦  «         d S rD   )r*   Ú	set_token)r2   r3   s     r5   r3   zOAuth2Client.token{   s   € àŒ×!Ò! %Ñ(Ô(Ð(Ð(Ð(r7   c                 óœ  — |€t          ¦   «         }| j                             dd¦  «        }|                     d|¦  «        }d|vr
| j        |d<   d|vr
| j        |d<   |r-|dk    r'| j        dk    rt          |¦  «        |d<   | j        |d<   | j        D ]}||vr|| j        v r| j        |         ||<   Œ t          |f| j
        ||d	œ|¤Ž}||fS )
a   Generate an authorization URL and state.

        :param url: Authorization endpoint url, must be HTTPS.
        :param state: An optional state string for CSRF protection. If not
                      given it will be generated for you.
        :param code_verifier: An optional code_verifier for code challenge.
        :param kwargs: Extra parameters to include.
        :return: authorization_url, state
        NÚresponse_typeÚcoder'   r&   ÚS256Úcode_challenger(   )r!   rH   r#   )r   r.   Úgetr,   r'   r&   r(   r   ÚEXTRA_AUTHORIZE_PARAMSr   r!   )r2   Úurlr#   Úcode_verifierÚkwargsrH   ÚkÚuris           r5   Úcreate_authorization_urlz%OAuth2Client.create_authorization_url   s   € ð ˆ=Ý"Ñ$Ô$ˆEàœ×)Ò)¨/¸6ÑBÔBˆØŸ
š
 ?°MÑBÔBˆØ Ð'Ð'Ø%)Ô%6ˆF�>Ñ"Ø˜&Ð Ð Ø"œjˆF�7‰Oàð 	I˜]¨fÒ4Ð4¸Ô9SÐW]Ò9]Ð9]Ý'AÀ-Ñ'PÔ'PˆFÐ#Ñ$Ø.2Ô.HˆFÐ*Ñ+àÔ,ð 	-ð 	-ˆAØ˜ˆˆ 1¨¬Ð#5Ð#5Ø œM¨!Ô,��q‘	øåØð#Øœ>¸Øð#ð #à!ð#ð #ˆð �EˆzÐr7   Ú ÚPOSTc                 ó  — |p| j         }|                     dd¦  «        }	|	rd|	v r|                      |	|¦  «        S |                      |¦  «        }
|	r"d|	v rd}t	          |	|¬¦  «        }|d         |d<   |€| j                             d¦  «        }|€t          |¦  «        }|| j        d<    | j        ||fi |¤Ž}|€|  	                    | j
        ¦  «        }|€t          }|€| j                             d	¦  «        } | j        |f||||d
œ|
¤ŽS )am  Generic method for fetching an access token from the token endpoint.

        :param url: Access Token endpoint URL, if not configured,
                    ``authorization_response`` is used to extract token from
                    its fragment (implicit way).
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param method: The HTTP method used to make the request. Defaults
                       to POST, but may also be GET. Other methods should
                       be added as needed.
        :param headers: Dict to default request headers with.
        :param auth: An auth tuple or method as accepted by requests.
        :param grant_type: Use specified grant_type to fetch token
        :return: A :class:`OAuth2Token` object (a dict too).
        Úauthorization_responseNú#zcode=Úauthorization_code)r#   rI   Ú
grant_typeÚtoken_endpoint)Úbodyr<   ÚmethodÚheaders)r#   r,   Útoken_from_fragmentÚ_extract_session_request_paramsr   r.   rL   Ú_guess_grant_typeÚ_prepare_token_endpoint_bodyrB   r$   ÚDEFAULT_HEADERSÚ_fetch_token)r2   rN   r\   r]   r^   r<   rZ   r#   rP   rW   Úsession_kwargsÚparamss               r5   Úfetch_tokenzOAuth2Client.fetch_token    sp  € ð" Ð#˜œˆà!'§¢Ð,DÀdÑ!KÔ!KÐØ!ð 	K cÐ-CÐ&CÐ&CØ×+Ò+Ð,BÀEÑJÔJÐJà×=Ò=¸fÑEÔEˆà!ð 	, gÐ1GÐ&GÐ&GØ-ˆJÝ6Ø&Øðñ ô ˆFð $ Fœ^ˆF�6‰NàÐØœ×*Ò*¨<Ñ8Ô8ˆJàÐÝ*¨6Ñ2Ô2ˆJØ*4ˆDŒM˜,Ñ'à0ˆtÔ0°°zÐLÐLÀVÐLÐLˆàˆ<Ø×#Ò# DÔ$CÑDÔDˆDàˆ?Ý%ˆGàˆ;Ø”-×#Ò#Ð$4Ñ5Ô5ˆCà ˆtÔ Øð
Ø ¨fØð
ð 
à-ð
ð 
ð 	
r7   c                 óœ   — t          ||¦  «        }d|v r0|                      |d         |                     d¦  «        ¬¦  «        ‚|| _        |S )NÚerrorÚerror_description©ri   Údescription)r	   Úoauth_error_classrL   r3   )r2   rW   r#   r3   s       r5   r_   z OAuth2Client.token_from_fragmentØ   s_   € Ý'Ð(>ÀÑFÔFˆØ�eÐÐØ×(Ò(Ø˜G”nØ!ŸIšIÐ&9Ñ:Ô:ð )ñ ô ð ð ˆŒ
Øˆr7   c                 ó„  — |                       |¦  «        }|p| j                             d¦  «        }d|vr| j        r
| j        |d<   t	          d|fd|i|¤Ž}|€t
                               ¦   «         }| j        d         D ]} ||||¦  «        \  }}}Œ|€|                      | j	        ¦  «        } | j
        |f||||dœ|¤ŽS )a	  Fetch a new access token using a refresh token.

        :param url: Refresh Token endpoint, must be HTTPS.
        :param refresh_token: The refresh_token to use.
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by requests.
        :param headers: Dict to default request headers with.
        :return: A :class:`OAuth2Token` object (a dict too).
        Úrefresh_tokenr&   Nr   )ro   r\   r^   r<   )r`   r3   rL   r&   r   rc   Úcopyr0   rB   r$   Ú_refresh_token)	r2   rN   ro   r\   r<   r^   rP   re   Úhooks	            r5   ro   zOAuth2Client.refresh_tokenâ   s  € ð ×=Ò=¸fÑEÔEˆØ%ÐH¨¬¯ª¸Ñ)HÔ)HˆØ˜&Ð Ð  T¤ZÐ Ø"œjˆF�7‰OÝ$Ø˜Tð
ð 
à'ð
à+1ð
ð 
ˆð
 ˆ?Ý%×*Ò*Ñ,Ô,ˆGàÔ(Ð)@ÔAð 	:ð 	:ˆDØ!%  c¨7°DÑ!9Ô!9ÑˆC�˜$˜$àˆ<Ø×#Ò# DÔ$CÑDÔDˆDà"ˆtÔ"Øð)Ø,°4ÀØð)ð )à'ð)ð )ð 	)r7   c                 ó„  — |                      ¦   «         sdS |                     d¦  «        }| j                             d¦  «        }|r|r|                      ||¬¦  «         dS | j                             d¦  «        dk    r?|d         }|                      |d¬¦  «        }| j        r|                      ||¬	¦  «         dS d S )
NTro   r[   ©ro   rZ   Úclient_credentialsÚaccess_token)rZ   )rv   )Ú
is_expiredrL   r.   ro   rg   r+   )r2   r3   ro   rN   rv   Ú	new_tokens         r5   Úensure_active_tokenz OAuth2Client.ensure_active_token  sá   € Ø×ÒÑ!Ô!ð 	Ø�4ØŸ	š	 /Ñ2Ô2ˆØŒm×ÒÐ 0Ñ1Ô1ˆØð 	˜Sð 	Ø×Ò˜s°-ÐÑ@Ô@Ð@Ø�4ØŒ]×Ò˜|Ñ,Ô,Ð0DÒDÐDØ  Ô0ˆLØ×(Ò(¨Ð9MÐ(ÑNÔNˆIØÔ ð HØ×!Ò! )¸,Ð!ÑGÔGÐGØ�4ð EÐDr7   c           	      ó,   —  | j         d|f|||||dœ|¤ŽS )a¶  Revoke token method defined via `RFC7009`_.

        :param url: Revoke Token endpoint, must be HTTPS.
        :param token: The token to be revoked.
        :param token_type_hint: The type of the token that to be revoked.
                                It can be "access_token" or "refresh_token".
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by requests.
        :param headers: Dict to default request headers with.
        :return: Revocation Response

        .. _`RFC7009`: https://tools.ietf.org/html/rfc7009
        r   ©r3   Útoken_type_hintr\   r<   r^   ©Ú_handle_token_hint©r2   rN   r3   r|   r\   r<   r^   rP   s           r5   Úrevoke_tokenzOAuth2Client.revoke_token  s@   € ð  'ˆtÔ&Ø" Cð=à¨Ø˜D¨'ð=ð =ð 6<ð=ð =ð 	=r7   c           	      ó,   —  | j         d|f|||||dœ|¤ŽS )aÛ  Implementation of OAuth 2.0 Token Introspection defined via `RFC7662`_.

        :param url: Introspection Endpoint, must be HTTPS.
        :param token: The token to be introspected.
        :param token_type_hint: The type of the token that to be revoked.
                                It can be "access_token" or "refresh_token".
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by requests.
        :param headers: Dict to default request headers with.
        :return: Introspection Response

        .. _`RFC7662`: https://tools.ietf.org/html/rfc7662
        r   r{   r}   r   s           r5   Úintrospect_tokenzOAuth2Client.introspect_token(  s@   € ð  'ˆtÔ&Ø&¨ð=à¨Ø˜D¨'ð=ð =ð 6<ð=ð =ð 	=r7   c                 óÒ   — |dk    r!| j         j                             |¦  «         dS || j        vrt	          d|| j        ¦  «        ‚| j        |                              |¦  «         dS )aè  Register a hook for request/response tweaking.

        Available hooks are:

        * access_token_response: invoked before token parsing.
        * refresh_token_request: invoked before refreshing token.
        * refresh_token_response: invoked before refresh token parsing.
        * protected_request: invoked before making a request.
        * revoke_token_request: invoked before revoking a token.
        * introspect_token_request: invoked before introspecting a token.
        Úprotected_requestNzHook type %s is not in %s.)r*   ÚhooksÚaddr0   r-   )r2   Ú	hook_typerr   s      r5   Úregister_compliance_hookz%OAuth2Client.register_compliance_hook=  s{   € ð Ð+Ò+Ð+ØŒOÔ!×%Ò% dÑ+Ô+Ð+ØˆFà˜DÔ0Ð0Ð0ÝÐ9Ø&¨Ô(<ñ>ô >ð >àÔ˜YÔ'×+Ò+¨DÑ1Ô1Ð1Ð1Ð1r7   c                 óì   — |j         dk    r|                     ¦   «          |                     ¦   «         }d|v r0|                      |d         |                     d¦  «        ¬¦  «        ‚|| _        | j        S )Niô  ri   rj   rk   )Ústatus_codeÚraise_for_statusÚjsonrm   rL   r3   )r2   Úrespr3   s      r5   Úparse_response_tokenz!OAuth2Client.parse_response_tokenR  s   € ØÔ˜sÒ"Ð"Ø×!Ò!Ñ#Ô#Ð#à—	’	‘”ˆØ�eÐÐØ×(Ò(Ø˜G”nØ!ŸIšIÐ&9Ñ:Ô:ð )ñ ô ð ð ˆŒ
ØŒzÐr7   c                 óŠ  — |                      ¦   «         dk    r2 | j        j        |ft          t	          |¦  «        ¦  «        ||dœ|¤Ž}nJd|v rd                     ||g¦  «        }nd                     ||g¦  «        } | j        j        ||f||dœ|¤Ž}| j        d         D ]} ||¦  «        }Œ|                      |¦  «        S )NrU   ©Údatar^   r<   ú?ú&)r^   r<   r   )	Úupperr    ÚpostÚdictr   ÚjoinÚrequestr0   rŽ   )	r2   rN   r\   r^   r<   r]   rP   r�   rr   s	            r5   rd   zOAuth2Client._fetch_token_  sô   € ð �<Š<‰>Œ>˜VÒ#Ð#Ø$�4”<Ô$Øð6Ý�z¨$Ñ/Ô/Ñ0Ô0Ø dð6ð 6à.4ð6ð 6ˆDˆDð �cˆzˆzØ—h’h  T˜{Ñ+Ô+��à—h’h  T˜{Ñ+Ô+�Ø'�4”<Ô'¨°ÐZ¸WÈ4ÐZÐZÐSYÐZÐZˆDàÔ(Ð)@ÔAð 	ð 	ˆDØ�4˜‘:”:ˆDˆDà×(Ò(¨Ñ.Ô.Ð.r7   c                 ó  —  | j         |f|||dœ|¤Ž}| j        d         D ]} ||¦  «        }Œ|                      |¦  «        }	d|	vr
|| j        d<   t	          | j        ¦  «        r|                      | j        |¬¦  «         | j        S )N)r\   r<   r^   r   ro   rt   )Ú
_http_postr0   rŽ   r3   Úcallabler+   )
r2   rN   ro   r\   r^   r<   rP   r�   rr   r3   s
             r5   rq   zOAuth2Client._refresh_tokenr  s¬   € àˆtŒ˜sÐT¨°DÀ'ÐTÐTÈVÐTÐTˆàÔ(Ð)AÔBð 	ð 	ˆDØ�4˜‘:”:ˆDˆDà×)Ò)¨$Ñ/Ô/ˆØ %Ð'Ð'Ø*7ˆDŒJ�Ñ'å�DÔ%Ñ&Ô&ð 	GØ×Ò˜dœj¸ÐÑFÔFÐFàŒzÐr7   c                 óv  — |€;| j         r4| j                              d¦  «        p| j                              d¦  «        }|€d}t          ||||¦  «        \  }}| j        |         D ]} ||||¦  «        \  }}}Œ|€|                      | j        ¦  «        }|                      |¦  «        }	 | j        ||f||dœ|	¤ŽS )Nro   rv   rT   )r<   r^   )r3   rL   r
   r0   rB   r%   r`   rš   )
r2   rr   rN   r3   r|   r\   r<   r^   rP   re   s
             r5   r~   zOAuth2Client._handle_token_hint‚  sô   € àˆ=˜TœZˆ=Ø”J—N’N ?Ñ3Ô3ÐU°t´z·~²~ÀnÑ7UÔ7UˆEàˆ<ØˆDå4Ø�? D¨'ñ3ô 3‰ˆˆgð Ô(¨Ô.ð 	:ð 	:ˆDØ!%  c¨7°DÑ!9Ô!9ÑˆC�˜$˜$àˆ<Ø×#Ò# DÔ$HÑIÔIˆDà×=Ò=¸fÑEÔEˆØˆtŒØ�ðEØ ¨'ðEð EØ5CðEð Eð 	Er7   c                 óŒ   — |dk    rd|vr
| j         |d<   t          ||fi |¤ŽS d|vr| j        r
| j        |d<   t          ||fi |¤ŽS )NrY   r'   r&   )r'   r   r&   )r2   r\   rZ   rP   s       r5   rb   z)OAuth2Client._prepare_token_endpoint_body—  ss   € ØÐ-Ò-Ð-Ø VÐ+Ð+Ø)-Ô):��~Ñ&Ý(¨°TÐDÐD¸VÐDÐDÐDà˜&Ð Ð  T¤ZÐ Ø"œjˆF�7‰OÝ$ Z°Ð@Ð@¸Ð@Ð@Ð@r7   c                 óV   — i }| j         D ]}||v r|                     |¦  «        ||<   Œ|S )zDExtract parameters for session object from the passing ``**kwargs``.)ÚSESSION_REQUEST_PARAMSr,   )r2   rP   ÚrvrQ   s       r5   r`   z,OAuth2Client._extract_session_request_params¡  s;   € àˆØÔ,ð 	&ð 	&ˆAØ�Fˆ{ˆ{ØŸ
š
 1™œ��1‘øØˆ	r7   c                 ód   —  | j         j        |ft          t          |¦  «        ¦  «        ||dœ|¤ŽS )Nr�   )r    r•   r–   r   )r2   rN   r\   r<   r^   rP   s         r5   rš   zOAuth2Client._http_post©  sH   € Ø ˆtŒ|Ô Øð2Ý�: dÑ+Ô+Ñ,Ô,Ø $ð2ð 2à*0ð2ð 2ð 	2r7   )NNNNNNNNNr   N)NN)NrT   rU   NNNNrD   )NrT   NN)NNNNN)rT   NNrU   )NNN)!Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   rA   r   r)   r   rm   rM   rŸ   r6   r=   rB   Úpropertyr3   ÚsetterrS   rg   r_   ro   ry   r€   r‚   rˆ   rŽ   rd   rq   r~   rb   r`   rš   © r7   r5   r   r      s  € € € € € ðð ð* #ÐØ ÐØ#ÐðÐð  Ðà>BØ,0Ø15ØRVØDHð	/ ð / ð / ð / ðb1ð 1ð 1ð
ð 
ð 
ð ð%ð %ñ „Xð%ð „\ð)ð )ñ „\ð)ðð ð ð ðB EIØ6:ð6
ð 6
ð 6
ð 6
ðpð ð ð ð ;=Ø)-ð )ð  )ð  )ð  )ðDð ð ð =AØ37ð=ð =ð =ð =ð* AEØ7;ð=ð =ð =ð =ð*2ð 2ð 2ð*ð ð ð =AØ"ð/ð /ð /ð /ð& HLØ ðð ð ð ð  IMØ9=ðEð Eð Eð Eð*Að Að Aðð ð ð2ð 2ð 2ð 2ð 2ð 2r7   r   c                 ó.   — d| v rd}nd| v rd| v rd}nd}|S )NrI   rY   ÚusernameÚpasswordru   r¨   )rP   rZ   s     r5   ra   ra   ¯  s;   € Ø�ÐÐØ)ˆ
ˆ
Ø	�vÐ	Ð	 *°Ð"6Ð"6Øˆ
ˆ
à)ˆ
ØÐr7   N)Úauthlib.common.securityr   Úauthlib.common.urlsr   Úrfc6749.parametersr   r   r   r	   Úrfc7009r
   Úrfc7636r   r<   r   r   Úbaser   rc   r   ra   r¨   r7   r5   ú<module>r²      s  ðØ 2Ð 2Ð 2Ð 2Ð 2Ð 2Ø *Ð *Ð *Ð *Ð *Ð *ðð ð ð ð ð ð ð ð ð ð ð ð 2Ð 1Ð 1Ð 1Ð 1Ð 1Ø /Ð /Ð /Ð /Ð /Ð /Ø 'Ð 'Ð 'Ð 'Ð 'Ð 'Ð 'Ð 'Ø Ð Ð Ð Ð Ð ð !ØEðð €ðX2ð X2ð X2ð X2ð X2ñ X2ô X2ð X2ðvð ð ð ð r7   