§
    ZŠtj>)  ã                   ó®   — d Z ddlZddlZddlZddlmZmZ ddlmZ ddl	m
Z
mZ ddlmZ dd	lmZ dd
lmZ  ej        e¦  «        Z G d„ de
¦  «        ZdS )zð
oauthlib.oauth2.rfc6749.endpoint.metadata
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

An implementation of the `OAuth 2.0 Authorization Server Metadata`.

.. _`OAuth 2.0 Authorization Server Metadata`: https://tools.ietf.org/html/rfc8414
é    Né   )Úgrant_typesÚutilsé   )ÚAuthorizationEndpoint)ÚBaseEndpointÚcatch_errors_and_unavailability)ÚIntrospectEndpoint)ÚRevocationEndpoint)ÚTokenEndpointc                   ó`   — e Zd ZdZi dfd„Ze	 	 dd„¦   «         Zdd„Zd	„ Zd
„ Z	d„ Z
d„ Zd„ ZdS )ÚMetadataEndpointa½  OAuth2.0 Authorization Server Metadata endpoint.

   This specification generalizes the metadata format defined by
   `OpenID Connect Discovery 1.0` in a way that is compatible
   with OpenID Connect Discovery while being applicable to a wider set
   of OAuth 2.0 use cases.  This is intentionally parallel to the way
   that OAuth 2.0 Dynamic Client Registration Protocol [`RFC7591`_]
   generalized the dynamic client registration mechanisms defined by
   OpenID Connect Dynamic Client Registration 1.0
   in a way that is compatible with it.

   .. _`OpenID Connect Discovery 1.0`: https://openid.net/specs/openid-connect-discovery-1_0.html
   .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
   Tc                 óð   — t          |t          ¦  «        sJ ‚|D ]}t          |t          ¦  «        sJ ‚Œt          j        | ¦  «         || _        || _        || _        |                      ¦   «         | _        d S )N)	Ú
isinstanceÚdictr   Ú__init__Úraise_errorsÚ	endpointsÚinitial_claimsÚvalidate_metadata_serverÚclaims)Úselfr   r   r   Úendpoints        úh/var/www/html/CA-Chatbot/venv/lib/python3.11/site-packages/oauthlib/oauth2/rfc6749/endpoints/metadata.pyr   zMetadataEndpoint.__init__(   s   € Ý˜&¥$Ñ'Ô'Ð'Ð'Ð'Ø!ð 	6ð 	6ˆHÝ˜h­Ñ5Ô5Ð5Ð5Ð5Ð5åÔ˜dÑ#Ô#Ð#Ø(ˆÔØ"ˆŒØ$ˆÔØ×3Ò3Ñ5Ô5ˆŒˆˆó    ÚGETNc                 óD   — dddœ}|t          j        | j        ¦  «        dfS )z!Create metadata response
        zapplication/jsonÚ*)zContent-TypezAccess-Control-Allow-OriginéÈ   )ÚjsonÚdumpsr   )r   ÚuriÚhttp_methodÚbodyÚheaderss        r   Úcreate_metadata_responsez)MetadataEndpoint.create_metadata_response3   s1   € ð /Ø+.ð
ð 
ˆð �œ
 4¤;Ñ/Ô/°Ð4Ð4r   Fc                 ó<  — | j         sd S ||vr&|r"t          d                     |¦  «        ¦  «        ‚d S |rŒt          j        ||         ¦  «        s)t          d                     |||         ¦  «        ¦  «        ‚d||         v sd||         v s
d||         v r)t          d                     |||         ¦  «        ¦  «        ‚d S |rF||                              d¦  «        s)t          d                     |||         ¦  «        ¦  «        ‚d S |rŽt          ||         t          ¦  «        s)t          d	                     |||         ¦  «        ¦  «        ‚||         D ]C}t          |t          ¦  «        s*t          d
                     |||         |¦  «        ¦  «        ‚ŒBd S d S )Nzkey {} is a mandatory metadata.zkey {}: {} must be an HTTPS URLú?ú&ú#z8key {}: {} must not contain query or fragment componentsÚhttpzkey {}: {} must be an URLzkey {}: {} must be an Arrayz/array {}: {} must contains only string (not {}))	r   Ú
ValueErrorÚformatr   Úis_secure_transportÚ
startswithr   ÚlistÚstr)r   ÚarrayÚkeyÚis_requiredÚis_listÚis_urlÚ	is_issuerÚelems           r   Úvalidate_metadataz"MetadataEndpoint.validate_metadata>   sü  € ØÔ ð 	ØˆFà�eÐÐØð PÝ Ð!B×!IÒ!IÈ#Ñ!NÔ!NÑOÔOÐOðPð Pð ð 	vÝÔ,¨U°3¬ZÑ8Ô8ð \Ý Ð!B×!IÒ!IÈ#ÈuÐUXÌzÑ!ZÔ!ZÑ[Ô[Ð[Ø�e˜C”jÐ Ð  C¨5°¬:Ð$5Ð$5¸ÀÀcÄ
Ð9JÐ9JÝ Ð![×!bÒ!bÐcfÐhmÐnqÔhrÑ!sÔ!sÑtÔtÐtð :KÐ9Jð ð 		vØ˜”:×(Ò(¨Ñ0Ô0ð VÝ Ð!<×!CÒ!CÀCÈÈsÌÑ!TÔ!TÑUÔUÐUðVð Vð ð 	vÝ˜e Cœj­$Ñ/Ô/ð XÝ Ð!>×!EÒ!EÀcÈ5ÐQTÌ:Ñ!VÔ!VÑWÔWÐWØ˜cœ
ð vð v�Ý! $­Ñ,Ô,ð vÝ$Ð%V×%]Ò%]Ð^aÐchÐilÔcmÐosÑ%tÔ%tÑuÔuÐuðvð		vð 	vðvð vr   c                 ó*  — | j                              |j                              ¦   «         ¦  «         |                     dddg¦  «         |                      |dd¬¦  «         |                      |dd¬¦  «         |                      |ddd¬¦  «         d	S )
zõ
        If the token endpoint is used in the grant type, the value of this
        parameter MUST be the same as the value of the "grant_type"
        parameter passed to the token endpoint defined in the grant type
        definition.
        Ú%token_endpoint_auth_methods_supportedÚclient_secret_postÚclient_secret_basicT©r5   Ú0token_endpoint_auth_signing_alg_values_supportedÚtoken_endpoint©r4   r6   N)Ú_grant_typesÚextendÚkeysÚ
setdefaultr9   ©r   r   r   s      r   Úvalidate_metadata_tokenz(MetadataEndpoint.validate_metadata_tokenW   s§   € ð 	Ô× Ò  Ô!6×!;Ò!;Ñ!=Ô!=Ñ>Ô>Ð>Ø×ÒÐAÐDXÐZoÐCpÑqÔqÐqà×Ò˜vÐ'NÐX\ÐÑ]Ô]Ð]Ø×Ò˜vÐ'YÐcgÐÑhÔhÐhØ×Ò˜vÐ'7ÀTÐRVÐÑWÔWÐWÐWÐWr   c           
      óØ  — |                      dt          t          d„ |j                             ¦   «         ¦  «        ¦  «        ¦  «         |                      dddg¦  «         d|d         v r| j                             d¦  «         |                      |ddd¬	¦  «         |                      |dd¬
¦  «         d|d         v r�|j        d         }t          |t          j
        ¦  «        st          |d¦  «        r|j        }|                      dt          |j                             ¦   «         ¦  «        ¦  «         |                      |dd¬
¦  «         |                      |ddd¬¦  «         d S )NÚresponse_types_supportedc                 ó   — | dk    S )NÚnone© )Úxs    r   ú<lambda>zBMetadataEndpoint.validate_metadata_authorization.<locals>.<lambda>g   s
   € °°V²€ r   Úresponse_modes_supportedÚqueryÚfragmentÚtokenÚimplicitT)r4   r5   r>   ÚcodeÚdefault_grantÚ code_challenge_methods_supportedÚauthorization_endpointrA   )rE   r0   ÚfilterÚ_response_typesrD   rB   Úappendr9   r   r   ÚAuthorizationCodeGrantÚhasattrrU   Ú_code_challenge_methods)r   r   r   Ú
code_grants       r   Úvalidate_metadata_authorizationz0MetadataEndpoint.validate_metadata_authorizatione   s’  € Ø×ÒÐ4Ý�vÐ&;Ð&;¸XÔ=U×=ZÒ=ZÑ=\Ô=\Ñ]Ô]Ñ^Ô^ñ	`ô 	`ð 	`à×ÒÐ4°wÀ
Ð6KÑLÔLÐLð
 �fÐ7Ô8Ð8Ð8ØÔ×$Ò$ ZÑ0Ô0Ð0à×Ò˜vÐ'AÈtÐ]aÐÑbÔbÐbØ×Ò˜vÐ'AÈ4ÐÑPÔPÐPØ�VÐ6Ô7Ð7Ð7Ø!Ô1°&Ô9ˆJÝ˜j­+Ô*LÑMÔMð 6ÕRYÐZdÐfuÑRvÔRvð 6Ø'Ô5�
à×ÒÐ@Ý" :Ô#E×#JÒ#JÑ#LÔ#LÑMÔMñOô Oð Oà×"Ò" 6Ð+MÐW[Ð"Ñ\Ô\Ð\Ø×Ò˜vÐ'?ÈTÐZ^ÐÑ_Ô_Ð_Ð_Ð_r   c                 óÈ   — |                      dddg¦  «         |                      |dd¬¦  «         |                      |dd¬¦  «         |                      |ddd¬¦  «         d S )	NÚ*revocation_endpoint_auth_methods_supportedr<   r=   Tr>   Ú5revocation_endpoint_auth_signing_alg_values_supportedÚrevocation_endpointrA   ©rE   r9   rF   s      r   Úvalidate_metadata_revocationz-MetadataEndpoint.validate_metadata_revocation|   sŠ   € Ø×ÒÐFØ/Ð1FÐGñ	Iô 	Ið 	Ið 	×Ò˜vÐ'SÐ]aÐÑbÔbÐbØ×Ò˜vÐ'^ÐhlÐÑmÔmÐmØ×Ò˜vÐ'<È$ÐW[ÐÑ\Ô\Ð\Ð\Ð\r   c                 óÈ   — |                      dddg¦  «         |                      |dd¬¦  «         |                      |dd¬¦  «         |                      |ddd¬¦  «         d S )	NÚ-introspection_endpoint_auth_methods_supportedr<   r=   Tr>   Ú8introspection_endpoint_auth_signing_alg_values_supportedÚintrospection_endpointrA   rd   rF   s      r   Úvalidate_metadata_introspectionz0MetadataEndpoint.validate_metadata_introspection„   sŠ   € Ø×ÒÐIØ/Ð1FÐGñ	Iô 	Ið 	Ið 	×Ò˜vÐ'VÐ`dÐÑeÔeÐeØ×Ò˜vÐ'aÐkoÐÑpÔpÐpØ×Ò˜vÐ'?ÈTÐZ^ÐÑ_Ô_Ð_Ð_Ð_r   c                 ój  — t          j        | j        ¦  «        }|                      |ddd¬¦  «         |                      |dd¬¦  «         |                      |dd¬¦  «         |                      |dd¬¦  «         |                      |d	d¬¦  «         |                      |d
d¬¦  «         |                      |dd¬¦  «         g | _        | j        D ]®}t          |t          ¦  «        r|                      ||¦  «         t          |t          ¦  «        r|  
                    ||¦  «         t          |t          ¦  «        r|                      ||¦  «         t          |t          ¦  «        r|                      ||¦  «         Œ¯|                     d| j        ¦  «         |                      |dd¬¦  «         |S )a¬	  
        Authorization servers can have metadata describing their
        configuration.  The following authorization server metadata values
        are used by this specification. More details can be found in
        `RFC8414 section 2`_ :

       issuer
          REQUIRED

       authorization_endpoint
          URL of the authorization server's authorization endpoint
          [`RFC6749#Authorization`_].  This is REQUIRED unless no grant types are supported
          that use the authorization endpoint.

       token_endpoint
          URL of the authorization server's token endpoint [`RFC6749#Token`_].  This
          is REQUIRED unless only the implicit grant type is supported.

       scopes_supported
          RECOMMENDED.

       response_types_supported
          REQUIRED.

       Other OPTIONAL fields:
          jwks_uri,
          registration_endpoint,
          response_modes_supported

       grant_types_supported
          OPTIONAL.  JSON array containing a list of the OAuth 2.0 grant
          type values that this authorization server supports.  The array
          values used are the same as those used with the "grant_types"
          parameter defined by "OAuth 2.0 Dynamic Client Registration
          Protocol" [`RFC7591`_].  If omitted, the default value is
          "["authorization_code", "implicit"]".

       token_endpoint_auth_methods_supported

       token_endpoint_auth_signing_alg_values_supported

       service_documentation

       ui_locales_supported

       op_policy_uri

       op_tos_uri

       revocation_endpoint

       revocation_endpoint_auth_methods_supported

       revocation_endpoint_auth_signing_alg_values_supported

       introspection_endpoint

       introspection_endpoint_auth_methods_supported

       introspection_endpoint_auth_signing_alg_values_supported

       code_challenge_methods_supported

       Additional authorization server metadata parameters MAY also be used.
       Some are defined by other specifications, such as OpenID Connect
       Discovery 1.0 [`OpenID.Discovery`_].

        .. _`RFC8414 section 2`: https://tools.ietf.org/html/rfc8414#section-2
        .. _`RFC6749#Authorization`: https://tools.ietf.org/html/rfc6749#section-3.1
        .. _`RFC6749#Token`: https://tools.ietf.org/html/rfc6749#section-3.2
        .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
        .. _`OpenID.Discovery`: https://openid.net/specs/openid-connect-discovery-1_0.html
        ÚissuerT)r4   r7   Újwks_uri)r6   Úscopes_supportedr>   Úservice_documentationÚui_locales_supportedÚop_policy_uriÚ
op_tos_uriÚgrant_types_supported)ÚcopyÚdeepcopyr   r9   rB   r   r   r   rG   r   r_   r   re   r
   rj   rE   rF   s      r   r   z)MetadataEndpoint.validate_metadata_serverŒ   sØ  € õT ”˜tÔ2Ñ3Ô3ˆØ×Ò˜v x¸TÈTÐÑRÔRÐRØ×Ò˜v z¸$ÐÑ?Ô?Ð?Ø×Ò˜vÐ'9À4ÐÑHÔHÐHØ×Ò˜vÐ'>ÀtÐÑLÔLÐLØ×Ò˜vÐ'=ÀtÐÑLÔLÐLØ×Ò˜v ¸tÐÑDÔDÐDØ×Ò˜v |¸DÐÑAÔAÐAàˆÔØœð 	Gð 	GˆHÝ˜(¥MÑ2Ô2ð ?Ø×,Ò,¨V°XÑ>Ô>Ð>Ý˜(Õ$9Ñ:Ô:ð GØ×4Ò4°V¸XÑFÔFÐFÝ˜(Õ$6Ñ7Ô7ð DØ×1Ò1°&¸(ÑCÔCÐCÝ˜(Õ$6Ñ7Ô7ð GØ×4Ò4°V¸XÑFÔFÐFøð 	×ÒÐ1°4Ô3DÑEÔEÐEØ×Ò˜vÐ'>ÈÐÑMÔMÐMØˆr   )r   NN)FFFF)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r	   r&   r9   rG   r_   re   rj   r   rL   r   r   r   r      sÔ   € € € € € ðð ð *,¸$ð 	6ð 	6ð 	6ð 	6ð %ØDHØ)-ð5ð 5ð 5ñ %Ô$ð5ðvð vð vð vð2Xð Xð Xð`ð `ð `ð.]ð ]ð ]ð`ð `ð `ðbð bð bð bð br   r   )ry   rt   r    ÚloggingÚ r   r   Úauthorizationr   Úbaser   r	   Ú
introspectr
   Ú
revocationr   rR   r   Ú	getLoggerrv   Úlogr   rL   r   r   ú<module>r‚      sô   ððð ð €€€Ø €€€Ø €€€à !Ð !Ð !Ð !Ð !Ð !Ð !Ð !Ø 0Ð 0Ð 0Ð 0Ð 0Ð 0Ø ?Ð ?Ð ?Ð ?Ð ?Ð ?Ð ?Ð ?Ø *Ð *Ð *Ð *Ð *Ð *Ø *Ð *Ð *Ð *Ð *Ð *Ø  Ð  Ð  Ð  Ð  Ð  à€gÔ˜Ñ!Ô!€ðWð Wð Wð Wð W�|ñ Wô Wð Wð Wð Wr   