§
    iÝ[fÙ	  ã                   ó^   — d dl mZ d dlmZ ddlmZ ddlmZ ddlm	Z	  G d„ de¦  «        Z
d	S )
é   )ÚUnsupportedTokenTypeError)ÚRevocationEndpointé    )ÚContinueIteration)ÚInvalidTokenError)ÚJWTBearerTokenValidatorc                   ó0   ‡ — e Zd ZdZdˆ fd„	Zd„ Zd„ Zˆ xZS )ÚJWTRevocationEndpointa  JWTRevocationEndpoint inherits from `RFC7009`_
    :class:`~authlib.oauth2.rfc7009.RevocationEndpoint`.

    The JWT access tokens cannot be revoked.
    If the submitted token is a JWT access token, then revocation returns
    a `invalid_token_error`.

    :param issuer: The issuer identifier.

    :param \*\*kwargs: Other parameters are inherited from
        :class:`~authlib.oauth2.rfc7009.RevocationEndpoint`.

    Plain text access tokens and other kind of tokens such as refresh_tokens
    will be ignored by this endpoint and passed to the next revocation endpoint::

        class MyJWTAccessTokenRevocationEndpoint(JWTRevocationEndpoint):
            def get_jwks(self):
                ...

        authorization_server.register_endpoint(
            MyJWTAccessTokenRevocationEndpoint(
                issuer="https://authorization-server.example.org",
            )
        )
        authorization_server.register_endpoint(MyRefreshTokenRevocationEndpoint)

    .. _RFC7009: https://tools.ietf.org/html/rfc7009
    Nc                 óL   •—  t          ¦   «         j        |d|i|¤Ž || _        d S )NÚserver)ÚsuperÚ__init__Úissuer)Úselfr   r   ÚargsÚkwargsÚ	__class__s        €úU/var/www/piapp/venv/lib/python3.11/site-packages/authlib/oauth2/rfc9068/revocation.pyr   zJWTRevocationEndpoint.__init__&   s/   ø€ Ø�‰ŒÔ˜$Ð8 vÐ8°Ð8Ð8Ð8ØˆŒˆˆó    c                 ó^  — |                       ||¦  «         |j                             d¦  «        dvrt          ¦   «         ‚t	          | j        d¬¦  «        }| j        |_        	 |                     |j        d         ¦  «         n# t          $ r t          ¦   «         ‚w xY wt          ¦   «         ‚)Ú Útoken_type_hint)Úaccess_tokenNN)r   Úresource_serverÚtoken)
Úcheck_paramsÚformÚgetr   r   r   Úget_jwksÚauthenticate_tokenr   r   )r   ÚrequestÚclientÚ	validators       r   r    z(JWTRevocationEndpoint.authenticate_token*   s¼   € à×Ò˜' 6Ñ*Ô*Ð*ð Œ<×ÒÐ-Ñ.Ô.Ð6LÐLÐLÝ#Ñ%Ô%Ð%å+°4´;ÐPTÐUÑUÔUˆ	Ø!œ]ˆ	Ôð	&Ø×(Ò(¨¬°gÔ)>Ñ?Ô?Ð?Ð?øõ !ð 	&ð 	&ð 	&Ý#Ñ%Ô%Ð%ð	&øøøõ (Ñ)Ô)Ð)s   Á$ B ÂBc                 ó   — t          ¦   «         ‚)zÕReturn the JWKs that will be used to check the JWT access token signature.
        Developers MUST re-implement this method::

            def get_jwks(self):
                return load_jwks("jwks.json")
        )ÚNotImplementedError)r   s    r   r   zJWTRevocationEndpoint.get_jwks?   s   € õ "Ñ#Ô#Ð#r   )N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r    r   Ú__classcell__)r   s   @r   r
   r
      se   ø€ € € € € ðð ð:ð ð ð ð ð ð*ð *ð *ð*$ð $ð $ð $ð $ð $ð $r   r
   N)Úrfc6749r   Úrfc7009r   Úauthlib.common.errorsr   Úauthlib.oauth2.rfc6750.errorsr   Ú&authlib.oauth2.rfc9068.token_validatorr   r
   © r   r   ú<module>r1      s”   ðØ /Ð /Ð /Ð /Ð /Ð /Ø (Ð (Ð (Ð (Ð (Ð (Ø 3Ð 3Ð 3Ð 3Ð 3Ð 3Ø ;Ð ;Ð ;Ð ;Ð ;Ð ;Ø JÐ JÐ JÐ JÐ JÐ Jð>$ð >$ð >$ð >$ð >$Ð.ñ >$ô >$ð >$ð >$ð >$r   