Ë
    ”ÂiT7  ã                   óÆ   — d Z ddlZddlZddlZddlmZ ddlmZ ddlmZ ddl	m
Z
 ddl	mZ d	Zd
ZdZdZdZdZdd„Zdd„Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zy)zÕauthlib.oauth1.rfc5849.signature.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This module represents a direct implementation of `section 3.4`_ of the spec.

.. _`section 3.4`: https://tools.ietf.org/html/rfc5849#section-3.4
é    N)Úto_bytes)Ú
to_unicode)Úurlparseé   ©Úescape)Úunescapez	HMAC-SHA1zRSA-SHA1Ú	PLAINTEXTÚHEADERÚQUERYÚBODYc                 ó*  — t        ||«      }g }|D ]9  \  }}|dv rŒ|j                  d«      rt        |«      }|j                  ||f«       Œ; t	        |«      }dj                  t        | j                  «       «      t        |«      t        |«      g«      S )aX  Generate signature base string from request, per `Section 3.4.1`_.

    For example, the HTTP request::

        POST /request?b5=%3D%253D&a3=a&c%40=&a2=r%20b HTTP/1.1
        Host: example.com
        Content-Type: application/x-www-form-urlencoded
        Authorization: OAuth realm="Example",
            oauth_consumer_key="9djdj82h48djs9d2",
            oauth_token="kkk9d7dh3k39sjv7",
            oauth_signature_method="HMAC-SHA1",
            oauth_timestamp="137131201",
            oauth_nonce="7d8f3e4a",
            oauth_signature="bYT5CMsGcbgUdFHObYMEfcx6bsw%3D"

        c2&a3=2+q

    is represented by the following signature base string (line breaks
    are for display purposes only)::

        POST&http%3A%2F%2Fexample.com%2Frequest&a2%3Dr%2520b%26a3%3D2%2520q
        %26a3%3Da%26b5%3D%253D%25253D%26c%2540%3D%26c2%3D%26oauth_consumer_
        key%3D9djdj82h48djs9d2%26oauth_nonce%3D7d8f3e4a%26oauth_signature_m
        ethod%3DHMAC-SHA1%26oauth_timestamp%3D137131201%26oauth_token%3Dkkk
        9d7dh3k39sjv7

    .. _`Section 3.4.1`: https://tools.ietf.org/html/rfc5849#section-3.4.1
    )Úoauth_signatureÚrealmÚoauth_ú&)Únormalize_base_string_uriÚ
startswithr	   ÚappendÚnormalize_parametersÚjoinr   Úupper)	ÚmethodÚuriÚparamsÚhostÚbase_string_uriÚunescaped_paramsÚkÚvÚnormalized_paramss	            úX/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth1/rfc5849/signature.pyÚconstruct_base_stringr#      s¥   € ô< 0°°TÓ:€Oð ÐØò (‰ˆˆ1àÐ,Ñ,Øð �<‰<˜Ô!Ü˜“ˆAØ×Ñ  A Õ'ð(ô -Ð-=Ó>Ðð �8‰8ä�6—<‘<“>Ó"Ü�?Ó#ÜÐ$Ó%ð	
óð ó    c                 óV  — t        | «      } t        j                  | «      \  }}}}}}|r|st        d«      ‚|sd}|j                  «       }|j                  «       }|�|j                  «       }d}d|v r|j	                  dd«      \  }}	||	f|v r|}t        j
                  ||||ddf«      S )a7  Normalize Base String URI per `Section 3.4.1.2`_.

    For example, the HTTP request::

        GET /r%20v/X?id=123 HTTP/1.1
        Host: EXAMPLE.COM:80

    is represented by the base string URI: "http://example.com/r%20v/X".

    In another example, the HTTPS request::

        GET /?q=1 HTTP/1.1
        Host: www.example.net:8080

    is represented by the base string URI: "https://www.example.net:8080/".

    .. _`Section 3.4.1.2`: https://tools.ietf.org/html/rfc5849#section-3.4.1.2

    The host argument overrides the netloc part of the uri argument.
    z$uri must include a scheme and netlocú/))ÚhttpÚ80)ÚhttpsÚ443ú:r   Ú )r   r   Ú
ValueErrorÚlowerÚsplitÚ
urlunparse)
r   r   ÚschemeÚnetlocÚpathr   ÚqueryÚfragmentÚdefault_portsÚports
             r"   r   r   V   sÅ   € ô* �S‹/€CÜ4<×4EÑ4EÀcÓ4JÑ1€FˆF�D˜& %¨ñ ™ÜÐ?Ó@Ð@ñ Øˆð �\‰\‹^€FØ�\‰\‹^€Fð ÐØ—‘“ˆð€Mð ˆf�}Ø—\‘\ # qÓ)‰
ˆˆdØ�Dˆ>˜]Ñ*ØˆFä×Ñ ¨°°f¸bÀ"ÐEÓFÐFr$   c                 óÞ   — | D ��cg c]  \  }}t        |«      t        |«      f‘Œ }}}|j                  «        |D ��cg c]  \  }}|› d|› �‘Œ }}}dj                  |«      S c c}}w c c}}w )a×
  Normalize parameters per `Section 3.4.1.3.2`_.

    For example, the list of parameters from the previous section would
    be normalized as follows:

    Encoded::

    +------------------------+------------------+
    |          Name          |       Value      |
    +------------------------+------------------+
    |           b5           |     %3D%253D     |
    |           a3           |         a        |
    |          c%40          |                  |
    |           a2           |       r%20b      |
    |   oauth_consumer_key   | 9djdj82h48djs9d2 |
    |       oauth_token      | kkk9d7dh3k39sjv7 |
    | oauth_signature_method |     HMAC-SHA1    |
    |     oauth_timestamp    |     137131201    |
    |       oauth_nonce      |     7d8f3e4a     |
    |           c2           |                  |
    |           a3           |       2%20q      |
    +------------------------+------------------+

    Sorted::

    +------------------------+------------------+
    |          Name          |       Value      |
    +------------------------+------------------+
    |           a2           |       r%20b      |
    |           a3           |       2%20q      |
    |           a3           |         a        |
    |           b5           |     %3D%253D     |
    |          c%40          |                  |
    |           c2           |                  |
    |   oauth_consumer_key   | 9djdj82h48djs9d2 |
    |       oauth_nonce      |     7d8f3e4a     |
    | oauth_signature_method |     HMAC-SHA1    |
    |     oauth_timestamp    |     137131201    |
    |       oauth_token      | kkk9d7dh3k39sjv7 |
    +------------------------+------------------+

    Concatenated Pairs::

    +-------------------------------------+
    |              Name=Value             |
    +-------------------------------------+
    |               a2=r%20b              |
    |               a3=2%20q              |
    |                 a3=a                |
    |             b5=%3D%253D             |
    |                c%40=                |
    |                 c2=                 |
    | oauth_consumer_key=9djdj82h48djs9d2 |
    |         oauth_nonce=7d8f3e4a        |
    |   oauth_signature_method=HMAC-SHA1  |
    |      oauth_timestamp=137131201      |
    |     oauth_token=kkk9d7dh3k39sjv7    |
    +-------------------------------------+

    and concatenated together into a single string (line breaks are for
    display purposes only)::

        a2=r%20b&a3=2%20q&a3=a&b5=%3D%253D&c%40=&c2=&oauth_consumer_key=9dj
        dj82h48djs9d2&oauth_nonce=7d8f3e4a&oauth_signature_method=HMAC-SHA1
        &oauth_timestamp=137131201&oauth_token=kkk9d7dh3k39sjv7

    .. _`Section 3.4.1.3.2`: https://tools.ietf.org/html/rfc5849#section-3.4.1.3.2
    ú=r   )r   Úsortr   )r   r   r    Ú
key_valuesÚparameter_partss        r"   r   r   �   ss   € ðR 6<×<©T¨Q°”6˜!“9œf Q›iÒ(Ð<€JÑ<ð
 ‡O�OÔð
 /9×9¡d a¨˜!˜˜A˜a˜S’zÐ9€OÑ9ð
 �8‰8�OÓ$Ð$ùó =ùó :s
   † A#¾A)c                 ó’   — | j                   j                  dd«      }t        | j                  | j                  | j
                  |«      S )z,Generate signature base string from request.ÚHostN)ÚheadersÚgetr#   r   r   r   )Úrequestr   s     r"   Úgenerate_signature_base_stringrB   ø   s5   € à�?‰?×Ñ˜v tÓ,€DÜ  §¡°·±¸g¿n¹nÈdÓSÐSr$   c                 ó"  — | }t        |xs d«      }|dz  }|t        |xs d«      z  }t        j                  t        |«      t        |«      t        j
                  «      }t        j                  |j                  «       «      dd }t        |«      S )a[  Generate signature via HMAC-SHA1 method, per `Section 3.4.2`_.

    The "HMAC-SHA1" signature method uses the HMAC-SHA1 signature
    algorithm as defined in `RFC2104`_::

        digest = HMAC - SHA1(key, text)

    .. _`RFC2104`: https://tools.ietf.org/html/rfc2104
    .. _`Section 3.4.2`: https://tools.ietf.org/html/rfc5849#section-3.4.2
    r,   r   Néÿÿÿÿ)
r   ÚhmacÚnewr   ÚhashlibÚsha1ÚbinasciiÚ
b2a_base64Údigestr   )Úbase_stringÚclient_secretÚtoken_secretÚtextÚkeyÚ	signatureÚsigs          r"   Úhmac_sha1_signaturerS   þ   s…   € ð" €Dô �Ò$ "Ó
%€Cð ˆ3�J€Cð
 Œ6�,Ò$ "Ó%Ñ%€Cä—‘œ #›¬°«¼¿¹ÓE€Iô ×
Ñ
˜i×.Ñ.Ó0Ó
1°#°2Ð
6€CÜ�c‹?Ðr$   c                 óŽ   — ddl m} t        | «      }  |t        | «      |«      }t        j                  |«      dd }t        |«      S )ar  Generate signature via RSA-SHA1 method, per `Section 3.4.3`_.

    The "RSA-SHA1" signature method uses the RSASSA-PKCS1-v1_5 signature
    algorithm as defined in `RFC3447, Section 8.2`_ (also known as
    PKCS#1), using SHA-1 as the hash function for EMSA-PKCS1-v1_5.  To
    use this method, the client MUST have established client credentials
    with the server that included its RSA public key (in a manner that is
    beyond the scope of this specification).

    .. _`Section 3.4.3`: https://tools.ietf.org/html/rfc5849#section-3.4.3
    .. _`RFC3447, Section 8.2`: https://tools.ietf.org/html/rfc3447#section-8.2
    r   )Ú	sign_sha1NrD   )ÚrsarU   r   rI   rJ   r   )rL   Úrsa_private_keyrU   ÚsrR   s        r"   Úrsa_sha1_signaturerY   +  sC   € õ ä˜;Ó'€KÙ”(˜;Ó'¨Ó9€AÜ
×
Ñ
˜aÓ
   "Ð
%€CÜ�c‹?Ðr$   c                 óR   — t        | xs d«      }|dz  }|t        |xs d«      z  }|S )aÊ  Generate signature via PLAINTEXT method, per `Section 3.4.4`_.

    The "PLAINTEXT" method does not employ a signature algorithm.  It
    MUST be used with a transport-layer mechanism such as TLS or SSL (or
    sent over a secure channel with equivalent protections).  It does not
    utilize the signature base string or the "oauth_timestamp" and
    "oauth_nonce" parameters.

    .. _`Section 3.4.4`: https://tools.ietf.org/html/rfc5849#section-3.4.4
    r,   r   r   )rM   rN   rQ   s      r"   Úplaintext_signaturer[   @  s;   € ô" �}Ò*¨Ó+€Ið �Ñ€Ið
 ”˜Ò*¨Ó+Ñ+€IàÐr$   c                 óZ   — t        |«      }t        || j                  | j                  «      S )zSign a HMAC-SHA1 signature.)rB   rS   rM   rN   ©ÚclientrA   rL   s      r"   Úsign_hmac_sha1r_   _  s'   € ä0°Ó9€KÜ˜{¨F×,@Ñ,@À&×BUÑBUÓVÐVr$   c                 óD   — t        |«      }t        || j                  «      S )z4Sign a RSASSA-PKCS #1 v1.5 base64 encoded signature.)rB   rY   Úrsa_keyr]   s      r"   Úsign_rsa_sha1rb   e  s   € ä0°Ó9€KÜ˜k¨6¯>©>Ó:Ð:r$   c                 óB   — t        | j                  | j                  «      S )zSign a PLAINTEXT signature.)r[   rM   rN   )r^   rA   s     r"   Úsign_plaintextrd   k  s   € ä˜v×3Ñ3°V×5HÑ5HÓIÐIr$   c                 óš   — t        | «      }t        || j                  | j                  «      }t	        j
                  || j                  «      S )zVerify a HMAC-SHA1 signature.)rB   rS   rM   rN   rE   Úcompare_digestrQ   )rA   rL   rR   s      r"   Úverify_hmac_sha1rg   p  s?   € ä0°Ó9€KÜ
˜k¨7×+@Ñ+@À'×BVÑBVÓ
W€CÜ×Ñ˜s G×$5Ñ$5Ó6Ð6r$   c                 ó®   — ddl m} t        | «      }t        j                  t        | j                  «      «      } ||t        |«      | j                  «      S )z6Verify a RSASSA-PKCS #1 v1.5 base64 encoded signature.r   )Úverify_sha1)rV   ri   rB   rI   Ú
a2b_base64r   rQ   Úrsa_public_key)rA   ri   rL   rR   s       r"   Úverify_rsa_sha1rl   w  sD   € å ä0°Ó9€KÜ
×
Ñ
œh w×'8Ñ'8Ó9Ó
:€CÙ�sœH [Ó1°7×3IÑ3IÓJÐJr$   c                 ó‚   — t        | j                  | j                  «      }t        j                  || j
                  «      S )zVerify a PLAINTEXT signature.)r[   rM   rN   rE   rf   rQ   )rA   rR   s     r"   Úverify_plaintextrn   €  s3   € ä
˜g×3Ñ3°W×5IÑ5IÓ
J€CÜ×Ñ˜s G×$5Ñ$5Ó6Ð6r$   )N)Ú__doc__rI   rG   rE   Úauthlib.common.encodingr   r   Úauthlib.common.urlsr   Úutilr   r	   ÚSIGNATURE_HMAC_SHA1ÚSIGNATURE_RSA_SHA1ÚSIGNATURE_PLAINTEXTÚSIGNATURE_TYPE_HEADERÚSIGNATURE_TYPE_QUERYÚSIGNATURE_TYPE_BODYr#   r   r   rB   rS   rY   r[   r_   rb   rd   rg   rl   rn   © r$   r"   ú<module>rz      s”   ðñó Û Û å ,Ý .Ý (å Ý à!Ð ØÐ Ø!Ð à Ð ØÐ ØÐ ó6órDGòNX%òvTò*òZò*ò>Wò;òJò
7òKó7r$   