§
    (ê[f½  ã                   óZ   — d Z ddlmZ ddlmZmZ  G d„ d¦  «        Z G d„ d¦  «        ZdS )	zè
    authlib.oauth2.rfc6749.resource_protector
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Implementation of Accessing Protected Resources per `Section 7`_.

    .. _`Section 7`: https://tools.ietf.org/html/rfc6749#section-7
é   )Úscope_to_list)ÚMissingAuthorizationErrorÚUnsupportedTokenTypeErrorc                   óF   — e Zd ZdZdZd	d„Zed„ ¦   «         Zd„ Zd„ Z	d„ Z
dS )
ÚTokenValidatorziBase token validator class. Subclass this validator to register
    into ResourceProtector instance.
    ÚbearerNc                 ó"   — || _         || _        d S ©N)ÚrealmÚextra_attributes)Úselfr   r   s      ú]/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth2/rfc6749/resource_protector.pyÚ__init__zTokenValidator.__init__   s   € ØˆŒ
Ø 0ˆÔÐÐó    c                 óÄ   — |sdS t          | ¦  «        } | sdS t          | ¦  «        } |D ]6}t          t          |¦  «        ¦  «        }|                      |¦  «        r dS Œ7dS )NFT)r   ÚsetÚ
issuperset)Útoken_scopesÚrequired_scopesÚscopeÚresource_scopess       r   Úscope_insufficientz!TokenValidator.scope_insufficient   sƒ   € àð 	Ø�5å$ \Ñ2Ô2ˆØð 	Ø�4å˜<Ñ(Ô(ˆØ$ð 	ð 	ˆEÝ!¥-°Ñ"6Ô"6Ñ7Ô7ˆOØ×&Ò& Ñ7Ô7ð Ø�u�uðð ˆtr   c                 ó   — t          ¦   «         ‚)a_  A method to query token from database with the given token string.
        Developers MUST re-implement this method. For instance::

            def authenticate_token(self, token_string):
                return get_token_from_database(token_string)

        :param token_string: A string to represent the access_token.
        :return: token
        ©ÚNotImplementedError)r   Útoken_strings     r   Úauthenticate_tokenz!TokenValidator.authenticate_token(   s   € õ "Ñ#Ô#Ð#r   c                 ó   — dS )a@  A method to validate if the HTTP request is valid or not. Developers MUST
        re-implement this method.  For instance, your server requires a
        "X-Device-Version" in the header::

            def validate_request(self, request):
                if 'X-Device-Version' not in request.headers:
                    raise InvalidRequestError()

        Usually, you don't have to detect if the request is valid or not. If you have
        to, you MUST re-implement this method.

        :param request: instance of HttpRequest
        :raise: InvalidRequestError
        N© )r   Úrequests     r   Úvalidate_requestzTokenValidator.validate_request4   s   € € € r   c                 ó   — t          ¦   «         ‚)a4  A method to validate if the authorized token is valid, if it has the
        permission on the given scopes. Developers MUST re-implement this method.
        e.g, check if token is expired, revoked::

            def validate_token(self, token, scopes, request):
                if not token:
                    raise InvalidTokenError()
                if token.is_expired() or token.is_revoked():
                    raise InvalidTokenError()
                if not match_token_scopes(token, scopes):
                    raise InsufficientScopeError()
        r   )r   ÚtokenÚscopesr    s       r   Úvalidate_tokenzTokenValidator.validate_tokenD   s   € õ "Ñ#Ô#Ð#r   r
   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__Ú
TOKEN_TYPEr   Ústaticmethodr   r   r!   r%   r   r   r   r   r      s�   € € € € € ðð ð €Jð1ð 1ð 1ð 1ð ðð ñ „\ðð 
$ð 
$ð 
$ðð ð ð $ð $ð $ð $ð $r   r   c                   ó2   — e Zd Zd„ Zdefd„Zd„ Zd„ Zd„ ZdS )ÚResourceProtectorc                 ó0   — i | _         d | _        d | _        d S r
   )Ú_token_validatorsÚ_default_realmÚ_default_auth_type)r   s    r   r   zResourceProtector.__init__U   s    € Ø!#ˆÔØ"ˆÔØ"&ˆÔÐÐr   Ú	validatorc                 ó‚   — | j         s|j        | _        |j        | _         |j        | j        vr|| j        |j        <   dS dS )z„Register a token validator for a given Authorization type.
        Authlib has a built-in BearerTokenValidator per rfc6750.
        N)r1   r   r0   r*   r/   )r   r2   s     r   Úregister_token_validatorz*ResourceProtector.register_token_validatorZ   sS   € ð Ô&ð 	;Ø"+¤/ˆDÔØ&/Ô&:ˆDÔ#àÔ tÔ'=Ð=Ð=Ø;DˆDÔ" 9Ô#7Ñ8Ð8Ð8ð >Ð=r   c                 ó–   — | j                              |                     ¦   «         ¦  «        }|st          | j        | j        ¦  «        ‚|S )z;Get token validator from registry for the given token type.)r/   ÚgetÚlowerr   r1   r0   )r   Ú
token_typer2   s      r   Úget_token_validatorz%ResourceProtector.get_token_validatore   sI   € àÔ*×.Ò.¨z×/?Ò/?Ñ/AÔ/AÑBÔBˆ	Øð 	ZÝ+¨DÔ,CÀTÔEXÑYÔYÐYØÐr   c                 ó0  — |j                              d¦  «        }|st          | j        | j        ¦  «        ‚|                     dd¦  «        }t          |¦  «        dk    rt          | j        | j        ¦  «        ‚|\  }}|                      |¦  «        }||fS )aË  Parse the token and token validator from request Authorization header.
        Here is an example of Authorization header::

            Authorization: Bearer a-token-string

        This method will parse this header, if it can find the validator for
        ``Bearer``, it will return the validator and ``a-token-string``.

        :return: validator, token_string
        :raise: MissingAuthorizationError
        :raise: UnsupportedTokenTypeError
        ÚAuthorizationNr   é   )	Úheadersr6   r   r1   r0   ÚsplitÚlenr   r9   )r   r    ÚauthÚtoken_partsr8   r   r2   s          r   Úparse_request_authorizationz-ResourceProtector.parse_request_authorizationl   sž   € ð Œ×"Ò" ?Ñ3Ô3ˆØð 	ZÝ+¨DÔ,CÀTÔEXÑYÔYÐYð —j’j  qÑ)Ô)ˆÝˆ{ÑÔ˜qÒ Ð Ý+¨DÔ,CÀTÔEXÑYÔYÐYà#.Ñ ˆ
�LØ×,Ò,¨ZÑ8Ô8ˆ	Ø˜,Ð&Ð&r   c                 óª   — |                       |¦  «        \  }}|                     |¦  «         |                     |¦  «        } |j        |||fi |¤Ž |S )z(Validate the request and return a token.)rB   r!   r   r%   )r   r$   r    Úkwargsr2   r   r#   s          r   r!   z"ResourceProtector.validate_request†   se   € à"&×"BÒ"BÀ7Ñ"KÔ"KÑˆ	�<Ø×"Ò" 7Ñ+Ô+Ð+Ø×,Ò,¨\Ñ:Ô:ˆØ ˆ	Ô  ¨°ÐBÐB¸6ÐBÐBÐBØˆr   N)	r&   r'   r(   r   r   r4   r9   rB   r!   r   r   r   r-   r-   T   sp   € € € € € ð'ð 'ð 'ð
	E°.ð 	Eð 	Eð 	Eð 	Eðð ð ð'ð 'ð 'ð4ð ð ð ð r   r-   N)r)   Úutilr   Úerrorsr   r   r   r-   r   r   r   ú<module>rG      sž   ððð ð  Ð Ð Ð Ð Ð Ø HÐ HÐ HÐ HÐ HÐ HÐ HÐ HðD$ð D$ð D$ð D$ð D$ñ D$ô D$ð D$ðN8ð 8ð 8ð 8ð 8ñ 8ô 8ð 8ð 8ð 8r   