Ë
    >²Xj+  ã                   óà   — d Z ddlZddlZddlZddlmZ ddlmZ ddlm	Z	 ddl
mZmZ ddlmZ  G d	„ d
e«      Z	 	 	 	 	 	 	 dd„Zd„ Zdd„Zdd„Zdd„Zd„ Zd„ Z G d„ d«      Z G d„ de«      Zy)zÿ
oauthlib.oauth2.rfc6749.tokens
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This module contains methods for adding two types of access tokens to requests.

- Bearer https://tools.ietf.org/html/rfc6750
- MAC https://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01
é    N)Ú
b2a_base64)Úurlparse)Úcommon)Úadd_params_to_qsÚadd_params_to_urié   )Úutilsc                   ó�   ‡ — e Zd Zd	ˆ fd„	Zed„ «       Zed„ «       Zed„ «       Zed„ «       Zed„ «       Z	ed„ «       Z
ed„ «       Zˆ xZS )
ÚOAuth2Tokenc                 óJ  •— t         ‰| �  |«       d | _        |j                  d«      r&t	        t        j                  |d   «      «      | _        |�Bt	        t        j                  |«      «      | _        | j                  €| j                  | _        y y | j                  | _        y )NÚscope)ÚsuperÚ__init__Ú
_new_scopeÚgetÚsetr	   Úscope_to_listÚ
_old_scope)ÚselfÚparamsÚ	old_scopeÚ	__class__s      €úd/var/www/html/content_generation/venv/lib/python3.12/site-packages/oauthlib/oauth2/rfc6749/tokens.pyr   zOAuth2Token.__init__   s„   ø€ Ü‰Ñ˜Ô ØˆŒØ�:‰:�gÔÜ!¤%×"5Ñ"5°f¸W±oÓ"FÓGˆDŒOØÐ Ü!¤%×"5Ñ"5°iÓ"@ÓAˆDŒOØ�‰Ð&ð #'§/¡/�•ð 'ð
 #Ÿo™oˆD�Oó    c                 ó4   — | j                   | j                  k7  S ©N)r   r   ©r   s    r   Úscope_changedzOAuth2Token.scope_changed&   s   € à�‰ $§/¡/Ñ1Ð1r   c                 ó@   — t        j                  | j                  «      S r   )r	   Úlist_to_scoper   r   s    r   r   zOAuth2Token.old_scope*   ó   € ä×"Ñ" 4§?¡?Ó3Ð3r   c                 ó,   — t        | j                  «      S r   )Úlistr   r   s    r   Ú
old_scopeszOAuth2Token.old_scopes.   ó   € ä�D—O‘OÓ$Ð$r   c                 ó@   — t        j                  | j                  «      S r   )r	   r    r   r   s    r   r   zOAuth2Token.scope2   r!   r   c                 ó,   — t        | j                  «      S r   )r#   r   r   s    r   ÚscopeszOAuth2Token.scopes6   r%   r   c                 óF   — t        | j                  | j                  z
  «      S r   )r#   r   r   r   s    r   Úmissing_scopeszOAuth2Token.missing_scopes:   ó   € ä�D—O‘O d§o¡oÑ5Ó6Ð6r   c                 óF   — t        | j                  | j                  z
  «      S r   )r#   r   r   r   s    r   Úadditional_scopeszOAuth2Token.additional_scopes>   r+   r   r   )Ú__name__Ú
__module__Ú__qualname__r   Úpropertyr   r   r$   r   r(   r*   r-   Ú__classcell__)r   s   @r   r   r      s”   ø„ õ.ð ñ2ó ð2ð ñ4ó ð4ð ñ%ó ð%ð ñ4ó ð4ð ñ%ó ð%ð ñ7ó ð7ð ñ7ó ô7r   r   c                 óX  — |j                  «       }t        j                  |«      \  }}|j                  «       dk(  rt        j
                  }n/|j                  «       dk(  rt        j                  }nt        d«      ‚|
dk(  r<|xs7 dj                  t        j                  |	«      t        j                  «       «      }n(t        j                  «       }t        j                  «       }t        |«      \  }}}}}}|r|dz   |z   n|}|�H|
dk(  rC|j                  d«      }t         ||«      j!                  «       «      dd	 j#                  d«      }nd
}g }|
dk(  r|j%                  |«       n"|j%                  «       |j%                  |«       |j%                  |j                  «       «       |j%                  |«       |j%                  |«       |j%                  |«       |
dk(  r|j%                  |«       |j%                  |xs d
«       dj'                  |«      dz   }t)        |t*        «      r|j                  d«      }t-        j.                  ||j                  d«      |«      }t        |j!                  «       «      dd	 j#                  d«      }g }|j%                  d| z  «       |
dk7  r|j%                  dz  «       |j%                  d|z  «       |r|j%                  d|z  «       |r|j%                  d|z  «       |j%                  d|z  «       |xs i }dj'                  |«      |d<   |S )a_  Add an `MAC Access Authentication`_ signature to headers.

    Unlike OAuth 1, this HMAC signature does not require inclusion of the
    request payload/body, neither does it use a combination of client_secret
    and token_secret but rather a mac_key provided together with the access
    token.

    Currently two algorithms are supported, "hmac-sha-1" and "hmac-sha-256",
    `extension algorithms`_ are not supported.

    Example MAC Authorization header, linebreaks added for clarity

    Authorization: MAC id="h480djs93hd8",
                       nonce="1336363200:dj83hs9s",
                       mac="bhCQXTVyfj5cmA9uKkPFx1zeOXM="

    .. _`MAC Access Authentication`: https://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01
    .. _`extension algorithms`: https://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01#section-7.1

    :param token:
    :param uri: Request URI.
    :param key: MAC given provided by token endpoint.
    :param http_method: HTTP Request method.
    :param nonce:
    :param headers: Request headers as a dictionary.
    :param body:
    :param ext:
    :param hash_algorithm: HMAC algorithm provided by token endpoint.
    :param issue_time: Time when the MAC credentials were issued (datetime).
    :param draft: MAC authentication specification version.
    :return: headers dictionary with the authorization field added.
    ú
hmac-sha-1zhmac-sha-256zunknown hash algorithmr   z{}:{}Ú?Nzutf-8éÿÿÿÿÚ Ú
zMAC id="%s"zts="%s"z
nonce="%s"zbodyhash="%s"zext="%s"zmac="%s"z, ÚAuthorization)Úupperr	   Úhost_from_uriÚlowerÚhashlibÚsha1Úsha256Ú
ValueErrorÚformatÚgenerate_ager   Úgenerate_nonceÚgenerate_timestampr   Úencoder   ÚdigestÚdecodeÚappendÚjoinÚ
isinstanceÚstrÚhmacÚnew)ÚtokenÚuriÚkeyÚhttp_methodÚnonceÚheadersÚbodyÚextÚhash_algorithmÚ
issue_timeÚdraftÚhostÚportÚhÚtsÚschÚnetÚpathÚparÚqueryÚfraÚrequest_uriÚbodyhashÚbaseÚbase_stringÚsignÚheaders                              r   Úprepare_mac_headerri   C   s¼  € ðP ×#Ñ#Ó%€KÜ×$Ñ$ SÓ)�J€Dˆ$à×ÑÓ Ò-Ü�L‰L‰Ø	×	Ñ	Ó	 >Ò	1Ü�N‰N‰äÐ1Ó2Ð2à�‚zØò C˜Ÿ™¬×(:Ñ(:¸:Ó(FÜ*0×*?Ñ*?Ó*AóC‰ô ×&Ñ&Ó(ˆÜ×%Ñ%Ó'ˆä&.¨s£mÑ#€Cˆˆd�C˜ á(-�$˜‘*˜uÒ$°4€Kð Ð˜E QšJØ�{‰{˜7Ó#ˆÜ™a ›gŸn™nÓ.Ó/°°Ð4×;Ñ;¸GÓD‰àˆð €DØ�‚zØ�‰�EÕà�‰�BŒØ�‰�EÔØ‡K�K�×!Ñ!Ó#Ô$Ø‡K�K�ÔØ‡K�K�ÔØ‡K�K�ÔØ�‚zØ�‰�HÔØ‡K�K�’	�rÔØ—)‘)˜D“/ DÑ(€Kô �#”sÔØ�j‰j˜Ó!ˆÜ�8‰8�C˜×+Ñ+¨GÓ4°aÓ8€DÜ�d—k‘k“mÓ$ S bÐ)×0Ñ0°Ó9€Dà€FØ
‡M�M�- %Ñ'Ô(Ø�‚zØ�‰�i "‘nÔ%Ø
‡M�M�, Ñ&Ô'ÙØ�‰�o¨Ñ0Ô1Ù
Ø�‰�j 3Ñ&Ô'Ø
‡M�M�*˜tÑ#Ô$àŠm˜€GØ#Ÿy™y¨Ó0€GˆOÑØ€Nr   c                 ó    — t        |d| fg«      S )a  Add a `Bearer Token`_ to the request URI.
    Not recommended, use only if client can't use authorization header or body.

    http://www.example.com/path?access_token=h480djs93hd8

    .. _`Bearer Token`: https://tools.ietf.org/html/rfc6750

    :param token:
    :param uri:
    Úaccess_token)r   )rN   rO   s     r   Úprepare_bearer_urirl   ­   s   € ô ˜S ^°UÐ$;Ð"=Ó>Ð>r   c                 ó"   — |xs i }d| z  |d<   |S )zëAdd a `Bearer Token`_ to the request URI.
    Recommended method of passing bearer tokens.

    Authorization: Bearer h480djs93hd8

    .. _`Bearer Token`: https://tools.ietf.org/html/rfc6750

    :param token:
    :param headers:
    z	Bearer %sr9   © )rN   rS   s     r   Úprepare_bearer_headersro   »   s!   € ð Šm˜€GØ*¨UÑ2€GˆOÑØ€Nr   c                 ó    — t        |d| fg«      S )z¯Add a `Bearer Token`_ to the request body.

    access_token=h480djs93hd8

    .. _`Bearer Token`: https://tools.ietf.org/html/rfc6750

    :param token:
    :param body:
    rk   )r   )rN   rT   s     r   Úprepare_bearer_bodyrq   Ë   s   € ô ˜D ^°UÐ$;Ð"=Ó>Ð>r   c                 ó*   — t        j                  «       S )zp
    :param request: OAuthlib request.
    :type request: oauthlib.common.Request
    :param refresh_token:
    )r   Úgenerate_token)ÚrequestÚrefresh_tokens     r   Úrandom_token_generatorrv   Ø   s   € ô × Ñ Ó"Ð"r   c                 ó   ‡ ‡— ˆˆ fd„}|S )z
    :param private_pem:
    c                 ó>   •— ‰| _         t        j                  ‰| «      S r   )Úclaimsr   Úgenerate_signed_token)rt   ÚkwargsÚprivate_pems    €€r   Úsigned_token_generatorz6signed_token_generator.<locals>.signed_token_generatorå   s   ø€ ØˆŒÜ×+Ñ+¨K¸ÓAÐAr   rn   )r|   r{   r}   s   `` r   r}   r}   á   s   ù€ õBð "Ð!r   c                 óæ   — d}d| j                   v rT| j                   j                  d«      j                  «       }t        |«      dk(  r|d   j	                  «       dk(  r|d   }|S | j
                  }|S )zç
    Helper function to extract a token from the request header.

    :param request: OAuthlib request.
    :type request: oauthlib.common.Request
    :return: Return the token or None if the Authorization header is malformed.
    Nr9   é   r   Úbearerr   )rS   r   ÚsplitÚlenr<   rk   )rt   rN   Úsplit_headers      r   Úget_token_from_headerr„   ì   su   € ð €Eà˜'Ÿ/™/Ñ)Ø—‘×*Ñ*¨?Ó;×AÑAÓCˆÜˆ|Ó Ò! l°1¡o×&;Ñ&;Ó&=ÀÒ&IØ  ‘OˆEð €Lð ×$Ñ$ˆà€Lr   c                   ó$   — e Zd ZdZdd„Zd„ Zd„ Zy)Ú	TokenBasern   c                 ó   — t        d«      ‚)Nú&Subclasses must implement this method.©ÚNotImplementedError)r   rt   ru   s      r   Ú__call__zTokenBase.__call__  s   € Ü!Ð"JÓKÐKr   c                 ó   — t        d«      ‚©úb
        :param request: OAuthlib request.
        :type request: oauthlib.common.Request
        rˆ   r‰   ©r   rt   s     r   Úvalidate_requestzTokenBase.validate_request  ó   € ô
 "Ð"JÓKÐKr   c                 ó   — t        d«      ‚r�   r‰   r�   s     r   Úestimate_typezTokenBase.estimate_type  r‘   r   N©F)r.   r/   r0   Ú	__slots__r‹   r�   r“   rn   r   r   r†   r†      s   „ Ø€IóLòLóLr   r†   c                   ó0   — e Zd ZdZ	 	 dd„Zdd„Zd„ Zd„ Zy)	ÚBearerToken)Úrequest_validatorÚtoken_generatorÚrefresh_token_generatorÚ
expires_inNc                 óp   — || _         |xs t        | _        |xs | j                  | _        |xs d| _        y )Ni  )r˜   rv   r™   rš   r›   )r   r˜   r™   r›   rš   s        r   r   zBearerToken.__init__  s<   € à!2ˆÔØ.ÒHÔ2HˆÔà#Ò; t×';Ñ';ð 	Ô$ð %Ò,¨ˆ�r   c                 ó  — d|v rt        j                  dt        «       t        | j                  «      r| j	                  |«      n| j                  }||_        | j                  |«      |ddœ}|j                  �dj                  |j                  «      |d<   |rK|j                  r+| j                  j                  |«      s|j                  |d<   n| j                  |«      |d<   |j                  |j                  xs i «       t        |«      S )zÁ
        Create a BearerToken, by default without refresh token.

        :param request: OAuthlib request.
        :type request: oauthlib.common.Request
        :param refresh_token:
        Ú
save_tokenzx`save_token` has been deprecated, it was not called internally.If you do, call `request_validator.save_token()` instead.ÚBearer)rk   r›   Ú
token_typeÚ r   ru   )ÚwarningsÚwarnÚDeprecationWarningÚcallabler›   r™   r(   rI   ru   r˜   Úrotate_refresh_tokenrš   ÚupdateÚextra_credentialsr   )r   rt   ru   r{   r›   rN   s         r   Úcreate_tokenzBearerToken.create_token$  só   € ð ˜6Ñ!Ü�M‰Mð Vä,ô.ô 2:¸$¿/¹/Ô1J�T—_‘_ WÔ-ÐPT×P_ÑP_ˆ
à'ˆÔð !×0Ñ0°Ó9Ø$Ø"ñ
ˆð �>‰>Ð%Ø ŸX™X g§n¡nÓ5ˆE�'‰NáØ×%Ò%Ø×.Ñ.×CÑCÀGÔLØ)0×)>Ñ)>��oÒ&à)-×)EÑ)EÀgÓ)N��oÑ&à�‰�W×.Ñ.Ò4°"Ô5Ü˜5Ó!Ð!r   c                 óf   — t        |«      }| j                  j                  ||j                  |«      S )rŽ   )r„   r˜   Úvalidate_bearer_tokenr(   )r   rt   rN   s      r   r�   zBearerToken.validate_requestK  s2   € ô
 & gÓ.ˆØ×%Ñ%×;Ñ;Ø�7—>‘> 7ó,ð 	,r   c                 óž   — |j                   j                  dd«      j                  d«      d   j                  «       dk(  ry|j                  �yy)rŽ   r9   r7   r¡   r   r€   é	   é   )rS   r   r�   r<   rk   r�   s     r   r“   zBearerToken.estimate_typeT  sK   € ð
 �?‰?×Ñ˜°Ó3×9Ñ9¸#Ó>¸qÑA×GÑGÓIÈXÒUØØ×!Ñ!Ð-Øàr   )NNNNr”   )r.   r/   r0   r•   r   r©   r�   r“   rn   r   r   r—   r—     s(   „ ð€Ið
 @DØ:>ó-ó%"òN,ó
r   r—   )NNNr7   r4   Nr   r   )r7   r”   )Ú__doc__r=   rL   r¢   Úbinasciir   Úurllib.parser   Úoauthlibr   Úoauthlib.commonr   r   r7   r	   Údictr   ri   rl   ro   rq   rv   r}   r„   r†   r—   rn   r   r   Ú<module>rµ      s‡   ðñó Û Û Ý Ý !å ß ?å ô*7�$ô *7ð\ "Ø#Ø ØØ&2Ø"&ØógòT?óó 
?ó#ò"ò÷(Lñ Lô*I�)õ Ir   