o
    í6Wj|]  ã                   @   s|   d dl Z d dlmZmZ d dlmZmZ d dlmZ d dlmZm	Z	 d dl
Z
e  e¡ZG dd„ deƒZG dd	„ d	e
jƒZdS )
é    N)Úgenerate_tokenÚ	urldecode)ÚWebApplicationClientÚInsecureTransportError)ÚLegacyApplicationClient)ÚTokenExpiredErrorÚis_secure_transportc                       s   e Zd Z‡ fdd„Z‡  ZS )ÚTokenUpdatedc                    s   t t| ƒ ¡  || _d S ©N)Úsuperr	   Ú__init__Útoken)Úselfr   ©Ú	__class__© úo/home/esfera/Documents/content_generation/venv/lib/python3.10/site-packages/requests_oauthlib/oauth2_session.pyr      s   
zTokenUpdated.__init__)Ú__name__Ú
__module__Ú__qualname__r   Ú__classcell__r   r   r   r   r	      s    r	   c                       sB  e Zd ZdZ										d&‡ fdd„	Zedd„ ƒZejdd„ ƒZdd	„ Zed
d„ ƒZ	e	jdd„ ƒZ	e	j
dd„ ƒZ	edd„ ƒZejdd„ ƒZedd„ ƒZejdd„ ƒZej
dd„ ƒZedd„ ƒZd'dd„Z															d(dd„Zdd„ Z							d)d d!„Z						d*‡ fd"d#„	Zd$d%„ Z‡  ZS )+ÚOAuth2Sessiona*  Versatile OAuth 2 extension to :class:`requests.Session`.

    Supports any grant type adhering to :class:`oauthlib.oauth2.Client` spec
    including the four core OAuth 2 grants.

    Can be used to create authorization urls, fetch tokens and access protected
    resources using the :class:`requests.Session` interface you are used to.

    - :class:`oauthlib.oauth2.WebApplicationClient` (default): Authorization Code Grant
    - :class:`oauthlib.oauth2.MobileApplicationClient`: Implicit Grant
    - :class:`oauthlib.oauth2.LegacyApplicationClient`: Password Credentials Grant
    - :class:`oauthlib.oauth2.BackendApplicationClient`: Client Credentials Grant

    Note that the only time you will be using Implicit Grant from python is if
    you are driving a user agent able to obtain URL fragments.
    Nc                    s²   t t| ƒjdi |¤Ž |pt||d�| _|pi | _|| _|| _|p"t| _	|| _
|| _|p-i | _|	| _|
| _| jdvrDtd | j| j¡ƒ‚dd„ | _tƒ tƒ tƒ tƒ tƒ dœ| _dS )	a˜  Construct a new OAuth 2 client session.

        :param client_id: Client id obtained during registration
        :param client: :class:`oauthlib.oauth2.Client` to be used. Default is
                       WebApplicationClient which is useful for any
                       hosted application but not mobile or desktop.
        :param scope: List of scopes you wish to request access to
        :param redirect_uri: Redirect URI you registered as callback
        :param token: Token dictionary, must include access_token
                      and token_type.
        :param state: State string used to prevent CSRF. This will be given
                      when creating the authorization url and must be supplied
                      when parsing the authorization response.
                      Can be either a string or a no argument callable.
        :auto_refresh_url: Refresh token endpoint URL, must be HTTPS. Supply
                           this if you wish the client to automatically refresh
                           your access tokens.
        :auto_refresh_kwargs: Extra arguments to pass to the refresh token
                              endpoint.
        :token_updater: Method with one argument, token, to be used to update
                        your token database on automatic token refresh. If not
                        set a TokenUpdated warning will be raised when a token
                        has been refreshed. This warning will carry the token
                        in its token argument.
        :param pkce: Set "S256" or "plain" to enable PKCE. Default is disabled.
        :param kwargs: Arguments to pass to the Session constructor.
        )r   )ÚS256ÚplainNzWrong value for {}(.., pkce={})c                 S   s   | S r
   r   )Úrr   r   r   Ú<lambda>^   s    z(OAuth2Session.__init__.<locals>.<lambda>)Úaccess_token_responseÚrefresh_token_responseÚprotected_requestÚrefresh_token_requestÚaccess_token_requestNr   )r   r   r   r   Ú_clientr   Ú_scopeÚredirect_urir   ÚstateÚ_stateÚauto_refresh_urlÚauto_refresh_kwargsÚtoken_updaterÚ_pkceÚAttributeErrorÚformatr   ÚauthÚsetÚcompliance_hook)r   Ú	client_idÚclientr&   r'   Úscoper#   r   r$   r(   ÚpkceÚkwargsr   r   r   r   $   s(   )




ûzOAuth2Session.__init__c                 C   s&   | j dur| j S | jdur| jjS dS )zBBy default the scope from the client is used, except if overriddenN)r"   r!   r1   ©r   r   r   r   r1   j   s
   

zOAuth2Session.scopec                 C   s
   || _ d S r
   )r"   )r   r1   r   r   r   r1   t   ó   
c                 C   sN   z|   ¡ | _t d| j¡ W | jS  ty&   | j | _t d| j¡ Y | jS w )z6Generates a state string to be used in authorizations.zGenerated new state %s.z&Re-using previously supplied state %s.)r$   r%   ÚlogÚdebugÚ	TypeErrorr4   r   r   r   Ú	new_statex   s   
ýýzOAuth2Session.new_statec                 C   ó   t | jdd ƒS )Nr/   ©Úgetattrr!   r4   r   r   r   r/   ‚   ó   zOAuth2Session.client_idc                 C   ó   || j _d S r
   ©r!   r/   ©r   Úvaluer   r   r   r/   †   ó   c                 C   ó
   | j `d S r
   r?   r4   r   r   r   r/   Š   r5   c                 C   r:   )Nr   r;   r4   r   r   r   r   Ž   r=   zOAuth2Session.tokenc                 C   s   || j _| j  |¡ d S r
   )r!   r   Úpopulate_token_attributesr@   r   r   r   r   ’   s   c                 C   r:   )NÚaccess_tokenr;   r4   r   r   r   rE   —   r=   zOAuth2Session.access_tokenc                 C   r>   r
   ©r!   rE   r@   r   r   r   rE   ›   rB   c                 C   rC   r
   rF   r4   r   r   r   rE   Ÿ   r5   c                 C   s
   t | jƒS )a€  Boolean that indicates whether this session has an OAuth token
        or not. If `self.authorized` is True, you can reasonably expect
        OAuth-protected requests to the resource to succeed. If
        `self.authorized` is False, you need the user to go through the OAuth
        authentication dance before OAuth-protected requests to the resource
        will succeed.
        )ÚboolrE   r4   r   r   r   Ú
authorized£   s   
	zOAuth2Session.authorizedc                 K   sf   |p|   ¡ }| jr!| j d¡| _| j|d< | jj| j| jd�|d< | jj|f| j| j|dœ|¤Ž|fS )aF  Form an authorization URL.

        :param url: Authorization endpoint url, must be HTTPS.
        :param state: An optional state string for CSRF protection. If not
                      given it will be generated for you.
        :param kwargs: Extra parameters to include.
        :return: authorization_url, state
        é+   Úcode_challenge_method)Úcode_verifierrJ   Úcode_challenge)r#   r1   r$   )	r9   r)   r!   Úcreate_code_verifierÚ_code_verifierÚcreate_code_challengeÚprepare_request_urir#   r1   )r   Úurlr$   r3   r   r   r   Úauthorization_url®   s&   	

þÿüûøzOAuth2Session.authorization_urlÚ ÚPOSTFc                 K   sº  t |ƒstƒ ‚|s|r| jj|| jd� | jj}n|s+t| jtƒr+| jj}|s+tdƒ‚| j	r<| j
du r7tdƒ‚| j
|d< t| jtƒrR|du rJtdƒ‚|du rRtdƒ‚|durZ||d< |durb||d	< |durm|du rld
}n|dur‹| j}|r‹t d|¡ |dur‚|nd}tj ||¡}|r•|dur•||d< | jjd%||| j|dœ|¤Ž}|pªdddœ}i | _i }| ¡ dkrÃtt|ƒƒ||	rÀdnd< n| ¡ dkrÒtt|ƒƒ|d< ntdƒ‚| jd D ]}t d|¡ ||||ƒ\}}}qÛ| jd%|||
|||||dœ|¤Ž}t d|j¡ t d|jj¡ t d|jj¡ t d|jj¡ t d|j|j¡ t d t| jd! ƒ¡ | jd! D ]}t d"|¡ ||ƒ}�q6| jj |j| j!d#� | jj| _t d$| j¡ | jS )&a  Generic method for fetching an access token from the token endpoint.

        If you are using the MobileApplicationClient you will want to use
        `token_from_fragment` instead of `fetch_token`.

        The current implementation enforces the RFC guidelines.

        :param token_url: Token endpoint URL, must use HTTPS.
        :param code: Authorization code (used by WebApplicationClients).
        :param authorization_response: Authorization response URL, the callback
                                       URL of the request back to you. Used by
                                       WebApplicationClients instead of code.
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by `requests`.
        :param username: Username required by LegacyApplicationClients to appear
                         in the request body.
        :param password: Password required by LegacyApplicationClients to appear
                         in the request body.
        :param method: The HTTP method used to make the request. Defaults
                       to POST, but may also be GET. Other methods should
                       be added as needed.
        :param force_querystring: If True, force the request body to be sent
            in the querystring instead.
        :param timeout: Timeout of the request in seconds.
        :param headers: Dict to default request headers with.
        :param verify: Verify SSL certificate.
        :param proxies: The `proxies` argument is passed onto `requests`.
        :param include_client_id: Should the request body include the
                                  `client_id` parameter. Default is `None`,
                                  which will attempt to autodetect. This can be
                                  forced to always include (True) or never
                                  include (False).
        :param client_secret: The `client_secret` paired to the `client_id`.
                              This is generally required unless provided in the
                              `auth` tuple. If the value is `None`, it will be
                              omitted from the request, however if the value is
                              an empty string, an empty string will be sent.
        :param cert: Client certificate to send for OAuth 2.0 Mutual-TLS Client
                     Authentication (draft-ietf-oauth-mtls). Can either be the
                     path of a file containing the private key and certificate or
                     a tuple of two filenames for certificate and key.
        :param kwargs: Extra parameters to include in the token request.
        :return: A token dict
        ©r$   z?Please supply either code or authorization_response parameters.NzFCode verifier is not found, authorization URL must be generated beforerK   zQ`LegacyApplicationClient` requires both the `username` and `password` parameters.zGThe required parameter `username` was supplied, but `password` was not.ÚusernameÚpasswordFTzIEncoding `client_id` "%s" with `client_secret` as Basic auth credentials.rS   Úclient_secret)ÚcodeÚbodyr#   Úinclude_client_idúapplication/jsonú!application/x-www-form-urlencoded©ÚAcceptzContent-TyperT   ÚparamsÚdataÚGETz%The method kwarg must be POST or GET.r    z&Invoking access_token_request hook %s.)ÚmethodrQ   ÚtimeoutÚheadersr,   ÚverifyÚproxiesÚcertz0Request to fetch token completed with status %s.zRequest url was %szRequest headers were %szRequest body was %sú(Response headers were %s and content %s.ú!Invoking %d token response hooks.r   úInvoking hook %s.©r1   zObtained token %s.r   )"r   r   r!   Úparse_request_uri_responser%   rY   Ú
isinstancer   Ú
ValueErrorr)   rN   r   r/   r6   r7   Úrequestsr,   ÚHTTPBasicAuthÚprepare_request_bodyr#   r   ÚupperÚdictr   r.   ÚrequestÚstatus_coderQ   re   rZ   ÚtextÚlenÚparse_request_body_responser1   )r   Ú	token_urlrY   Úauthorization_responserZ   r,   rV   rW   rc   Úforce_querystringrd   re   rf   rg   r[   rX   rh   r3   r/   Úrequest_kwargsÚhookr   r   r   r   Úfetch_tokenÊ   sÌ   Aÿ
ÿ
ÿ
ÿÿ€ýüûþÿÿø	÷þ
zOAuth2Session.fetch_tokenc                 C   s"   | j j|| jd� | j j| _| jS )z¼Parse token from the URI fragment, used by MobileApplicationClients.

        :param authorization_response: The full URL of the redirect back to you
        :return: A token dict
        rU   )r!   rm   r%   r   )r   r{   r   r   r   Útoken_from_fragment›  s
   ÿ
z!OAuth2Session.token_from_fragmentc	              
   K   sb  |st dƒ‚t|ƒstƒ ‚|p| j d¡}t d| j¡ |	 | j¡ | j	j
d||| jdœ|	¤Ž}t d|¡ |du r?ddd	œ}| jd
 D ]}
t d|
¡ |
|||ƒ\}}}qD| j|tt|ƒƒ||||d|d�}t d|j¡ t d|j|j¡ t dt| jd ƒ¡ | jd D ]}
t d|
¡ |
|ƒ}q‡| j	j|j| jd�| _d| jvr®t d¡ || jd< | jS )aô  Fetch a new access token using a refresh token.

        :param token_url: The token endpoint, must be HTTPS.
        :param refresh_token: The refresh_token to use.
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by `requests`.
        :param timeout: Timeout of the request in seconds.
        :param headers: A dict of headers to be used by `requests`.
        :param verify: Verify SSL certificate.
        :param proxies: The `proxies` argument will be passed to `requests`.
        :param kwargs: Extra parameters to include in the token request.
        :return: A token dict
        z'No token endpoint set for auto_refresh.Úrefresh_tokenz*Adding auto refresh key word arguments %s.)rZ   r�   r1   z&Prepared refresh token request body %sNr\   r]   r^   r   z'Invoking refresh_token_request hook %s.T)ra   r,   rd   re   rf   Úwithhold_tokenrg   z2Request to refresh token completed with status %s.ri   rj   r   rk   rl   z)No new refresh token given. Re-using old.r   )ro   r   r   r   Úgetr6   r7   r'   Úupdater!   Úprepare_refresh_bodyr1   r.   Úpostrt   r   rv   re   rw   rx   ry   )r   rz   r�   rZ   r,   rd   re   rf   rg   r3   r~   r   r   r   r   r�   §  s\   ÿÿÿþ
ø
þ



zOAuth2Session.refresh_tokenc	              	      sŽ  t |ƒstƒ ‚| jr¢|s¢t dt| jd ƒ¡ | jd D ]}
t d|
¡ |
|||ƒ\}}}qt d| j¡ z| jj||||d�\}}}W n] t	y¡   | j
ržt d| j
¡ |	 dd¡}|rp|rp|du rpt d	|¡ tj ||¡}| j| j
fd|i|	¤Ž}| jršt d
|| j¡ |  |¡ | jj||||d�\}}}nt|ƒ‚‚ Y nw t d||¡ t d||¡ t d|	¡ tt| ƒj||f|||dœ|	¤ŽS )z<Intercept all requests and add the OAuth 2 token if present.z-Invoking %d protected resource request hooks.r   rk   zAdding token %s to request.)Úhttp_methodrZ   re   z1Auto refresh is set, attempting to refresh at %s.r,   NzEEncoding client_id "%s" with client_secret as Basic auth credentials.zUpdating token to %s using %s.z"Requesting url %s using method %s.z Supplying headers %s and data %sz&Passing through key word arguments %s.)re   ra   Úfiles)r   r   r   r6   r7   rx   r.   r!   Ú	add_tokenr   r&   Úpoprp   r,   rq   r�   r(   r	   r   r   ru   )r   rc   rQ   ra   re   r‚   r/   rX   rˆ   r3   r~   r,   r   r   r   r   ru   ö  sr   
þÿþþÿÿÿÿ
ÿúé
ÿÿÿzOAuth2Session.requestc                 C   s,   || j vrtd|| j ƒ‚| j |  |¡ dS )a  Register a hook for request/response tweaking.

        Available hooks are:
            access_token_response invoked before token parsing.
            refresh_token_response invoked before refresh token parsing.
            protected_request invoked before making a request.
            access_token_request invoked before making a token fetch request.
            refresh_token_request invoked before making a refresh request.

        If you find a new hook is needed please send a GitHub PR request
        or open an issue.
        zHook type %s is not in %s.N)r.   ro   Úadd)r   Ú	hook_typer~   r   r   r   Úregister_compliance_hook:  s
   
ÿz&OAuth2Session.register_compliance_hook)
NNNNNNNNNNr
   )NNrS   NNNrT   FNNNNNNN)NrS   NNNNN)NNFNNN)r   r   r   Ú__doc__r   Úpropertyr1   Úsetterr9   r/   Údeleterr   rE   rH   rR   r   r€   r�   ru   r�   r   r   r   r   r   r      sŽ    õF
	













ï R
÷S÷Dr   )ÚloggingÚoauthlib.commonr   r   Úoauthlib.oauth2r   r   r   r   r   rp   Ú	getLoggerr   r6   ÚWarningr	   ÚSessionr   r   r   r   r   Ú<module>   s    
