§
    (ê[fz.  ã                   ór   — d dl mZ ddlmZ ddlmZmZ ddlmZm	Z	m
Z
mZ ddlmZ  G d„ d¦  «        Zd	„ Zd
S )é    )ÚContinueIterationé   )ÚClientAuthentication)ÚOAuth2RequestÚJsonRequest)ÚOAuth2ErrorÚInvalidScopeErrorÚUnsupportedResponseTypeErrorÚUnsupportedGrantTypeError)Úscope_to_listc                   ó¸   — e Zd ZdZdd„Zd„ Zd„ Z	 	 dd„Zd„ Zdd
„Z	d„ Z
d„ Zd„ Zdefd„Zdefd„Zd„ Zdd„Zdd„Zd„ Zd„ Zdd„Zd„ Zdd„Zdd„Zdd„Zd„ ZdS ) ÚAuthorizationServerz¬Authorization server that handles Authorization Endpoint and Token
    Endpoint.

    :param scopes_supported: A list of supported scopes by this authorization server.
    Nc                 óZ   — || _         i | _        d | _        g | _        g | _        i | _        d S ©N)Úscopes_supportedÚ_token_generatorsÚ_client_authÚ_authorization_grantsÚ_token_grantsÚ
_endpoints)Úselfr   s     ú_/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth2/rfc6749/authorization_server.pyÚ__init__zAuthorizationServer.__init__   s5   € Ø 0ˆÔØ!#ˆÔØ ˆÔØ%'ˆÔ"ØˆÔØˆŒˆˆó    c                 ó   — t          ¦   «         ‚)z¦Query OAuth client by client_id. The client model class MUST
        implement the methods described by
        :class:`~authlib.oauth2.rfc6749.ClientMixin`.
        ©ÚNotImplementedError)r   Ú	client_ids     r   Úquery_clientz AuthorizationServer.query_client   s   € õ
 "Ñ#Ô#Ð#r   c                 ó   — t          ¦   «         ‚)z:Define function to save the generated token into database.r   )r   ÚtokenÚrequests      r   Ú
save_tokenzAuthorizationServer.save_token"   ó   € å!Ñ#Ô#Ð#r   Tc                 ó²   — | j                              |¦  «        }|s| j                              d¦  «        }|st          d¦  «        ‚ |||||||¬¦  «        S )a�  Generate the token dict.

        :param grant_type: current requested grant_type.
        :param client: the client that making the request.
        :param user: current authorized user.
        :param expires_in: if provided, use this value as expires_in.
        :param scope: current requested scope.
        :param include_refresh_token: should refresh_token be included.
        :return: Token dict
        ÚdefaultzNo configured token generator)Ú
grant_typeÚclientÚuserÚscopeÚ
expires_inÚinclude_refresh_token)r   ÚgetÚRuntimeError)r   r'   r(   r)   r*   r+   r,   Úfuncs           r   Úgenerate_tokenz"AuthorizationServer.generate_token&   s|   € ð Ô%×)Ò)¨*Ñ5Ô5ˆØð 	9àÔ)×-Ò-¨iÑ8Ô8ˆDØð 	@ÝÐ>Ñ?Ô?Ð?àˆtØ!¨&°tÀ5Ø!Ð9NðPñ Pô Pð 	Pr   c                 ó   — || j         |<   dS )aâ  Register a function as token generator for the given ``grant_type``.
        Developers MUST register a default token generator with a special
        ``grant_type=default``::

            def generate_bearer_token(grant_type, client, user=None, scope=None,
                                      expires_in=None, include_refresh_token=True):
                token = {'token_type': 'Bearer', 'access_token': ...}
                if include_refresh_token:
                    token['refresh_token'] = ...
                ...
                return token

            authorization_server.register_token_generator('default', generate_bearer_token)

        If you register a generator for a certain grant type, that generator will only works
        for the given grant type::

            authorization_server.register_token_generator('client_credentials', generate_bearer_token)

        :param grant_type: string name of the grant type
        :param func: a function to generate token
        N)r   )r   r'   r/   s      r   Úregister_token_generatorz,AuthorizationServer.register_token_generator>   s   € ð. .2ˆÔ˜zÑ*Ð*Ð*r   r!   c                 ó~   — | j         € | j        rt          | j        ¦  «        | _         |                       |||¦  «        S )z’Authenticate client via HTTP request information with the given
        methods, such as ``client_secret_basic``, ``client_secret_post``.
        )r   r   r   )r   r"   ÚmethodsÚendpoints       r   Úauthenticate_clientz'AuthorizationServer.authenticate_clientW   s@   € ð ÔÐ$¨Ô):Ð$Ý 4°TÔ5FÑ GÔ GˆDÔØ× Ò  ¨'°8Ñ<Ô<Ð<r   c                 óŠ   — | j         € | j        rt          | j        ¦  «        | _         | j                              ||¦  «         dS )af  Add more client auth method. The default methods are:

        * none: The client is a public client and does not have a client secret
        * client_secret_post: The client uses the HTTP POST parameters
        * client_secret_basic: The client uses HTTP Basic

        :param method: Name of the Auth method
        :param func: Function to authenticate the client

        The auth method accept two parameters: ``query_client`` and ``request``,
        an example for this method::

            def authenticate_client_via_custom(query_client, request):
                client_id = request.headers['X-Client-Id']
                client = query_client(client_id)
                do_some_validation(client)
                return client

            authorization_server.register_client_auth_method(
                'custom', authenticate_client_via_custom)
        N)r   r   r   Úregister)r   Úmethodr/   s      r   Úregister_client_auth_methodz/AuthorizationServer.register_client_auth_method_   sG   € ð, ÔÐ$¨Ô):Ð$Ý 4°TÔ5FÑ GÔ GˆDÔàÔ×"Ò" 6¨4Ñ0Ô0Ð0Ð0Ð0r   c                 ó   — dS )zFReturn a URI for the given error, framework may implement this method.N© ©r   r"   Úerrors      r   Úget_error_uriz!AuthorizationServer.get_error_uriz   s   € àˆtr   c                 ó   — t          ¦   «         ‚)z]Framework integration can re-implement this method to support
        signal system.
        r   )r   ÚnameÚargsÚkwargss       r   Úsend_signalzAuthorizationServer.send_signal~   s   € õ "Ñ#Ô#Ð#r   Úreturnc                 ó   — t          ¦   «         ‚)zàThis method MUST be implemented in framework integrations. It is
        used to create an OAuth2Request instance.

        :param request: the "request" instance in framework
        :return: OAuth2Request instance
        r   ©r   r"   s     r   Úcreate_oauth2_requestz)AuthorizationServer.create_oauth2_request„   ó   € õ "Ñ#Ô#Ð#r   c                 ó   — t          ¦   «         ‚)zÜThis method MUST be implemented in framework integrations. It is
        used to create an HttpRequest instance.

        :param request: the "request" instance in framework
        :return: HttpRequest instance
        r   rG   s     r   Úcreate_json_requestz'AuthorizationServer.create_json_request�   rI   r   c                 ó   — t          ¦   «         ‚)z=Return HTTP response. Framework MUST implement this function.r   )r   ÚstatusÚbodyÚheaderss       r   Úhandle_responsez#AuthorizationServer.handle_response–   r$   r   c                 óÆ   — |rZ| j         rUt          t          |¦  «        ¦  «        }t          | j         ¦  «                             |¦  «        st	          |¬¦  «        ‚dS dS dS )zŠValidate if requested scope is supported by Authorization Server.
        Developers CAN re-write this method to meet your needs.
        )ÚstateN)r   Úsetr   Ú
issupersetr	   )r   r*   rR   Úscopess       r   Úvalidate_requested_scopez,AuthorizationServer.validate_requested_scopeš   s{   € ð ð 	5�TÔ*ð 	5Ý� uÑ-Ô-Ñ.Ô.ˆFÝ�tÔ,Ñ-Ô-×8Ò8¸Ñ@Ô@ð 5Ý'¨eÐ4Ñ4Ô4Ð4ð	5ð 	5ð 	5ð 	5ð5ð 5r   c                 óº   — t          |d¦  «        r| j                             ||f¦  «         t          |d¦  «        r| j                             ||f¦  «         dS dS )aÿ  Register a grant class into the endpoint registry. Developers
        can implement the grants in ``authlib.oauth2.rfc6749.grants`` and
        register with this method::

            class AuthorizationCodeGrant(grants.AuthorizationCodeGrant):
                def authenticate_user(self, credential):
                    # ...

            authorization_server.register_grant(AuthorizationCodeGrant)

        :param grant_cls: a grant class.
        :param extensions: extensions for the grant class.
        Úcheck_authorization_endpointÚcheck_token_endpointN)Úhasattrr   Úappendr   )r   Ú	grant_clsÚ
extensionss      r   Úregister_grantz"AuthorizationServer.register_grant£   ss   € õ �9Ð<Ñ=Ô=ð 	GØÔ&×-Ò-¨y¸*Ð.EÑFÔFÐFÝ�9Ð4Ñ5Ô5ð 	?ØÔ×%Ò% y°*Ð&=Ñ>Ô>Ð>Ð>Ð>ð	?ð 	?r   c                 óÀ   — t          |t          ¦  «        r || ¦  «        }n| |_        | j                             |j        g ¦  «        }|                     |¦  «         dS )zÚAdd extra endpoint to authorization server. e.g.
        RevocationEndpoint::

            authorization_server.register_endpoint(RevocationEndpoint)

        :param endpoint_cls: A endpoint class or instance.
        N)Ú
isinstanceÚtypeÚserverr   Ú
setdefaultÚENDPOINT_NAMEr[   )r   r5   Ú	endpointss      r   Úregister_endpointz%AuthorizationServer.register_endpoint¶   s`   € õ �h¥Ñ%Ô%ð 	#Ø�x ‘~”~ˆHˆHà"ˆHŒOà”O×.Ò.¨xÔ/EÀrÑJÔJˆ	Ø×Ò˜Ñ"Ô"Ð"Ð"Ð"r   c                 ó–   — | j         D ].\  }}|                     |¦  «        rt          |||| ¦  «        c S Œ/t          |j        ¦  «        ‚)z‹Find the authorization grant for current request.

        :param request: OAuth2Request instance.
        :return: grant instance
        )r   rX   Ú_create_grantr
   Úresponse_type©r   r"   r\   r]   s       r   Úget_authorization_grantz+AuthorizationServer.get_authorization_grantÆ   se   € ð (,Ô'Að 	Kð 	KÑ#ˆY˜
Ø×5Ò5°gÑ>Ô>ð KÝ$ Y°
¸GÀTÑJÔJÐJÐJÐJðKå*¨7Ô+@ÑAÔAÐAr   c                 ó�   — |                       |¦  «        }||_        |                      |¦  «        }|                     ¦   «          |S )z“Validate current HTTP request for authorization page. This page
        is designed for resource owner to grant or deny the authorization.
        )rH   r)   rk   Úvalidate_consent_request)r   r"   Úend_userÚgrants       r   Úget_consent_grantz%AuthorizationServer.get_consent_grantÑ   sH   € ð ×,Ò,¨WÑ5Ô5ˆØˆŒà×,Ò,¨WÑ5Ô5ˆØ×&Ò&Ñ(Ô(Ð(Øˆr   c                 ó–   — | j         D ].\  }}|                     |¦  «        rt          |||| ¦  «        c S Œ/t          |j        ¦  «        ‚)zƒFind the token grant for current request.

        :param request: OAuth2Request instance.
        :return: grant instance
        )r   rY   rh   r   r'   rj   s       r   Úget_token_grantz#AuthorizationServer.get_token_grantÜ   se   € ð (,Ô'9ð 	Kð 	KÑ#ˆY˜
Ø×-Ò-¨gÑ6Ô6ð KÝ$ Y°
¸GÀTÑJÔJÐJÐJÐJðKå'¨Ô(:Ñ;Ô;Ð;r   c                 ó*  — || j         vrt          d|› d�¦  «        ‚| j         |         }|D ]f}|                     |¦  «        }	  | j         ||¦  «        Ž c S # t          $ r Y Œ9t
          $ r"}|                      ||¦  «        cY d}~c S d}~ww xY wdS )z­Validate endpoint request and create endpoint response.

        :param name: Endpoint name
        :param request: HTTP request instance.
        :return: Response
        zThere is no "z" endpoint.N)r   r.   Úcreate_endpoint_requestrP   r   r   Úhandle_error_response)r   rA   r"   re   r5   r>   s         r   Úcreate_endpoint_responsez,AuthorizationServer.create_endpoint_responseç   sò   € ð �t”Ð&Ð&ÝÐ@¨tÐ@Ð@Ð@ÑAÔAÐAà”O DÔ)ˆ	Ø!ð 	Bð 	BˆHØ×6Ò6°wÑ?Ô?ˆGðBØ+�tÔ+¨X¨X°gÑ->Ô->Ð?Ð?Ð?Ð?øÝ$ð ð ð Ø�Ýð Bð Bð BØ×1Ò1°'¸5ÑAÔAÐAÐAÐAÐAÐAÐAÐAÐAøøøøðBøøøð	Bð 	Bs$   ÁAÁ
BÁ%	BÁ.BÂBÂBc                 ó¢  — t          |t          ¦  «        s|                      |¦  «        }	 |                      |¦  «        }n-# t          $ r }|                      ||¦  «        cY d}~S d}~ww xY w	 |                     ¦   «         }|                     ||¦  «        } | j        |Ž S # t          $ r }|                      ||¦  «        cY d}~S d}~ww xY w)zõValidate authorization request and create authorization response.

        :param request: HTTP request instance.
        :param grant_user: if granted, it is resource owner. If denied,
            it is None.
        :returns: Response
        N)
r`   r   rH   rk   r
   ru   Úvalidate_authorization_requestÚcreate_authorization_responserP   r   )r   r"   Ú
grant_userro   r>   Úredirect_urirB   s          r   ry   z1AuthorizationServer.create_authorization_responseû   s  € õ ˜'¥=Ñ1Ô1ð 	:Ø×0Ò0°Ñ9Ô9ˆGð	>Ø×0Ò0°Ñ9Ô9ˆEˆEøÝ+ð 	>ð 	>ð 	>Ø×-Ò-¨g°uÑ=Ô=Ð=Ð=Ð=Ð=Ð=Ð=øøøøð	>øøøð	>Ø ×?Ò?ÑAÔAˆLØ×6Ò6°|ÀZÑPÔPˆDØ'�4Ô'¨Ð.Ð.øÝð 	>ð 	>ð 	>Ø×-Ò-¨g°uÑ=Ô=Ð=Ð=Ð=Ð=Ð=Ð=øøøøð	>øøøs;   ¬A Á
A,ÁA'Á!A,Á'A,Á03B$ Â$
CÂ.C	ÃCÃ	Cc                 ót  — |                       |¦  «        }	 |                      |¦  «        }n-# t          $ r }|                      ||¦  «        cY d}~S d}~ww xY w	 |                     ¦   «          |                     ¦   «         } | j        |Ž S # t          $ r }|                      ||¦  «        cY d}~S d}~ww xY w)ziValidate token request and create token response.

        :param request: HTTP request instance
        N)rH   rr   r   ru   Úvalidate_token_requestÚcreate_token_responserP   r   )r   r"   ro   r>   rB   s        r   r~   z)AuthorizationServer.create_token_response  sñ   € ð
 ×,Ò,¨WÑ5Ô5ˆð	>Ø×(Ò(¨Ñ1Ô1ˆEˆEøÝ(ð 	>ð 	>ð 	>Ø×-Ò-¨g°uÑ=Ô=Ð=Ð=Ð=Ð=Ð=Ð=øøøøð	>øøøð	>Ø×(Ò(Ñ*Ô*Ð*Ø×.Ò.Ñ0Ô0ˆDØ'�4Ô'¨Ð.Ð.øÝð 	>ð 	>ð 	>Ø×-Ò-¨g°uÑ=Ô=Ð=Ð=Ð=Ð=Ð=Ð=øøøøð	>øøøs8   —- ­
A·AÁAÁAÁ1B Â
B7ÂB2Â,B7Â2B7c                 óP   —  | j          ||                      ||¦  «        ¦  «        Ž S r   )rP   r?   r=   s      r   ru   z)AuthorizationServer.handle_error_response$  s,   € Ø#ˆtÔ# U U¨4×+=Ò+=¸gÀuÑ+MÔ+MÑ%NÔ%NÐOÐOr   r   )NNNT)r!   )NN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r#   r0   r2   r6   r:   r?   rD   r   rH   r   rK   rP   rV   r^   rf   rk   rp   rr   rv   ry   r~   ru   r<   r   r   r   r      sÇ  € € € € € ðð ð
ð ð ð ð$ð $ð $ð$ð $ð $ð CGØ>BðPð Pð Pð Pð02ð 2ð 2ð2=ð =ð =ð =ð1ð 1ð 1ð6ð ð ð$ð $ð $ð$°ð $ð $ð $ð $ð$¨kð $ð $ð $ð $ð$ð $ð $ð5ð 5ð 5ð 5ð?ð ?ð ?ð ?ð&#ð #ð #ð 	Bð 	Bð 	Bð	ð 	ð 	ð 	ð	<ð 	<ð 	<ðBð Bð Bð Bð(>ð >ð >ð >ð.>ð >ð >ð >ð$Pð Pð Pð Pð Pr   r   c                 óB   —  | ||¦  «        }|r|D ]} ||¦  «         Œ|S r   r<   )r\   r]   r"   rb   ro   Úexts         r   rh   rh   (  s>   € ØˆI�g˜vÑ&Ô&€EØð Øð 	ð 	ˆCØˆC�‰JŒJˆJˆJØ€Lr   N)Úauthlib.common.errorsr   r6   r   Úrequestsr   r   Úerrorsr   r	   r
   r   Úutilr   r   rh   r<   r   r   ú<module>rŠ      sã   ðØ 3Ð 3Ð 3Ð 3Ð 3Ð 3Ø 5Ð 5Ð 5Ð 5Ð 5Ð 5Ø 0Ð 0Ð 0Ð 0Ð 0Ð 0Ð 0Ð 0ðð ð ð ð ð ð ð ð ð ð ð ð  Ð Ð Ð Ð Ð ðXPð XPð XPð XPð XPñ XPô XPð XPðvð ð ð ð r   