o
    ë6Wj>)  ã                   @   sŠ   d Z ddlZddlZddlZddlmZmZ ddlmZ ddl	m
Z
mZ ddlmZ dd	lmZ dd
lmZ e e¡ZG dd„ de
ƒZdS )zð
oauthlib.oauth2.rfc6749.endpoint.metadata
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

An implementation of the `OAuth 2.0 Authorization Server Metadata`.

.. _`OAuth 2.0 Authorization Server Metadata`: https://tools.ietf.org/html/rfc8414
é    Né   )Úgrant_typesÚutilsé   )ÚAuthorizationEndpoint)ÚBaseEndpointÚcatch_errors_and_unavailability)ÚIntrospectEndpoint)ÚRevocationEndpoint)ÚTokenEndpointc                   @   sb   e Zd ZdZi dfdd„Ze		ddd„ƒZdd
d„Zdd„ Zdd„ Z	dd„ Z
dd„ Zdd„ ZdS )ÚMetadataEndpointa½  OAuth2.0 Authorization Server Metadata endpoint.

   This specification generalizes the metadata format defined by
   `OpenID Connect Discovery 1.0` in a way that is compatible
   with OpenID Connect Discovery while being applicable to a wider set
   of OAuth 2.0 use cases.  This is intentionally parallel to the way
   that OAuth 2.0 Dynamic Client Registration Protocol [`RFC7591`_]
   generalized the dynamic client registration mechanisms defined by
   OpenID Connect Dynamic Client Registration 1.0
   in a way that is compatible with it.

   .. _`OpenID Connect Discovery 1.0`: https://openid.net/specs/openid-connect-discovery-1_0.html
   .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
   Tc                 C   sP   t |tƒsJ ‚|D ]	}t |tƒsJ ‚q	t | ¡ || _|| _|| _|  ¡ | _d S )N)	Ú
isinstanceÚdictr   Ú__init__Úraise_errorsÚ	endpointsÚinitial_claimsÚvalidate_metadata_serverÚclaims)Úselfr   r   r   Úendpoint© r   úy/home/esfera/Documents/content_generation/venv/lib/python3.10/site-packages/oauthlib/oauth2/rfc6749/endpoints/metadata.pyr   (   s   
zMetadataEndpoint.__init__ÚGETNc                 C   s   dddœ}|t  | j¡dfS )z!Create metadata response
        zapplication/jsonÚ*)zContent-TypezAccess-Control-Allow-OriginéÈ   )ÚjsonÚdumpsr   )r   ÚuriÚhttp_methodÚbodyÚheadersr   r   r   Úcreate_metadata_response3   s   þz)MetadataEndpoint.create_metadata_responseFc                 C   s  | j sd S ||vr|rtd |¡ƒ‚d S |rEt || ¡s'td ||| ¡ƒ‚d|| v s9d|| v s9d|| v rCtd ||| ¡ƒ‚d S |rZ||  d¡sXtd ||| ¡ƒ‚d S |r„t|| tƒsmtd	 ||| ¡ƒ‚|| D ]}t|tƒsƒtd
 ||| |¡ƒ‚qqd S d S )Nzkey {} is a mandatory metadata.zkey {}: {} must be an HTTPS URLú?ú&ú#z8key {}: {} must not contain query or fragment componentsÚhttpzkey {}: {} must be an URLzkey {}: {} must be an Arrayz/array {}: {} must contains only string (not {}))	r   Ú
ValueErrorÚformatr   Úis_secure_transportÚ
startswithr   ÚlistÚstr)r   ÚarrayÚkeyÚis_requiredÚis_listÚis_urlÚ	is_issuerÚelemr   r   r   Úvalidate_metadata>   s2   ÿ$ÿÿ
ÿüz"MetadataEndpoint.validate_metadatac                 C   sX   | j  |j  ¡ ¡ | dddg¡ | j|ddd� | j|ddd� | j|dddd� d	S )
zõ
        If the token endpoint is used in the grant type, the value of this
        parameter MUST be the same as the value of the "grant_type"
        parameter passed to the token endpoint defined in the grant type
        definition.
        Ú%token_endpoint_auth_methods_supportedÚclient_secret_postÚclient_secret_basicT©r0   Ú0token_endpoint_auth_signing_alg_values_supportedÚtoken_endpoint©r/   r1   N)Ú_grant_typesÚextendÚkeysÚ
setdefaultr4   ©r   r   r   r   r   r   Úvalidate_metadata_tokenW   s
   z(MetadataEndpoint.validate_metadata_tokenc                 C   sØ   |  dttdd„ |j ¡ ƒƒ¡ |  dddg¡ d|d v r$| j d¡ | j|dd	d	d
� | j|dd	d� d|d v ra|jd }t|t	j
ƒsNt|dƒrN|j}|  dt|j ¡ ƒ¡ | j|dd	d� | j|dd	d	d� d S )NÚresponse_types_supportedc                 S   s   | dkS )NÚnoner   )Úxr   r   r   Ú<lambda>g   s    zBMetadataEndpoint.validate_metadata_authorization.<locals>.<lambda>Úresponse_modes_supportedÚqueryÚfragmentÚtokenÚimplicitT)r/   r0   r8   ÚcodeÚdefault_grantÚ code_challenge_methods_supportedÚauthorization_endpointr;   )r?   r+   ÚfilterÚ_response_typesr>   r<   Úappendr4   r   r   ÚAuthorizationCodeGrantÚhasattrrL   Ú_code_challenge_methods)r   r   r   Ú
code_grantr   r   r   Úvalidate_metadata_authorizatione   s"   ÿ
ÿz0MetadataEndpoint.validate_metadata_authorizationc                 C   óF   |  dddg¡ | j|ddd� | j|ddd� | j|dddd� d S )	NÚ*revocation_endpoint_auth_methods_supportedr6   r7   Tr8   Ú5revocation_endpoint_auth_signing_alg_values_supportedÚrevocation_endpointr;   ©r?   r4   r@   r   r   r   Úvalidate_metadata_revocation|   ó   ÿz-MetadataEndpoint.validate_metadata_revocationc                 C   rW   )	NÚ-introspection_endpoint_auth_methods_supportedr6   r7   Tr8   Ú8introspection_endpoint_auth_signing_alg_values_supportedÚintrospection_endpointr;   r[   r@   r   r   r   Úvalidate_metadata_introspection„   r]   z0MetadataEndpoint.validate_metadata_introspectionc                 C   s
  t  | j¡}| j|dddd� | j|ddd� | j|ddd� | j|ddd� | j|d	dd� | j|d
dd� | j|ddd� g | _| jD ].}t|tƒrR|  ||¡ t|t	ƒr]|  
||¡ t|tƒrh|  ||¡ t|tƒrs|  ||¡ qE| d| j¡ | j|ddd� |S )a¬	  
        Authorization servers can have metadata describing their
        configuration.  The following authorization server metadata values
        are used by this specification. More details can be found in
        `RFC8414 section 2`_ :

       issuer
          REQUIRED

       authorization_endpoint
          URL of the authorization server's authorization endpoint
          [`RFC6749#Authorization`_].  This is REQUIRED unless no grant types are supported
          that use the authorization endpoint.

       token_endpoint
          URL of the authorization server's token endpoint [`RFC6749#Token`_].  This
          is REQUIRED unless only the implicit grant type is supported.

       scopes_supported
          RECOMMENDED.

       response_types_supported
          REQUIRED.

       Other OPTIONAL fields:
          jwks_uri,
          registration_endpoint,
          response_modes_supported

       grant_types_supported
          OPTIONAL.  JSON array containing a list of the OAuth 2.0 grant
          type values that this authorization server supports.  The array
          values used are the same as those used with the "grant_types"
          parameter defined by "OAuth 2.0 Dynamic Client Registration
          Protocol" [`RFC7591`_].  If omitted, the default value is
          "["authorization_code", "implicit"]".

       token_endpoint_auth_methods_supported

       token_endpoint_auth_signing_alg_values_supported

       service_documentation

       ui_locales_supported

       op_policy_uri

       op_tos_uri

       revocation_endpoint

       revocation_endpoint_auth_methods_supported

       revocation_endpoint_auth_signing_alg_values_supported

       introspection_endpoint

       introspection_endpoint_auth_methods_supported

       introspection_endpoint_auth_signing_alg_values_supported

       code_challenge_methods_supported

       Additional authorization server metadata parameters MAY also be used.
       Some are defined by other specifications, such as OpenID Connect
       Discovery 1.0 [`OpenID.Discovery`_].

        .. _`RFC8414 section 2`: https://tools.ietf.org/html/rfc8414#section-2
        .. _`RFC6749#Authorization`: https://tools.ietf.org/html/rfc6749#section-3.1
        .. _`RFC6749#Token`: https://tools.ietf.org/html/rfc6749#section-3.2
        .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
        .. _`OpenID.Discovery`: https://openid.net/specs/openid-connect-discovery-1_0.html
        ÚissuerT)r/   r2   Újwks_uri)r1   Úscopes_supportedr8   Úservice_documentationÚui_locales_supportedÚop_policy_uriÚ
op_tos_uriÚgrant_types_supported)ÚcopyÚdeepcopyr   r4   r<   r   r   r   rA   r   rV   r
   r\   r	   ra   r?   r@   r   r   r   r   Œ   s,   J




€z)MetadataEndpoint.validate_metadata_server)r   NN)FFFF)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r"   r4   rA   rV   r\   ra   r   r   r   r   r   r      s    ÿ

r   )ro   rj   r   ÚloggingÚ r   r   Úauthorizationr   Úbaser   r   Ú
introspectr	   Ú
revocationr
   rI   r   Ú	getLoggerrl   Úlogr   r   r   r   r   Ú<module>   s    
