Ë
    ”ÂiúI  ã                   ó¬   — d dl mZ d dlmZ ddlmZ ddlmZ ddlmZ ddl	m
Z
 ddl	mZ dd	l	mZ dd
l	mZ ddlmZ ddlmZ dddœZ G d„ d«      Zd„ Zy)é    )Úgenerate_token)Ú
url_decodeé   )Ú
ClientAuth)Ú	TokenAuth)ÚOAuth2Error)Ú!parse_authorization_code_response)Úparse_implicit_response)Úprepare_grant_uri)Úprepare_token_request)Úprepare_revoke_token_request)Úcreate_s256_code_challengezapplication/jsonz/application/x-www-form-urlencoded;charset=UTF-8)ÚAcceptzContent-Typec                   ó,  — e Zd ZdZeZeZeZ	dZ
g Z	 	 	 	 	 	 	 	 	 	 	 	 dd„Zd„ Zd„ Zed„ «       Zej"                  d„ «       Zdd	„Z	 	 	 	 	 	 	 dd
„Zdd„Z	 dd„Zdd„Z	 	 	 	 	 dd„Z	 	 	 	 	 dd„Zd„ Zd„ Z	 dd„Z	 d d„Z	 	 	 	 	 dd„Zd„ Zd„ Zd!d„Z d„ Z!y)"ÚOAuth2Clienta
  Construct a new OAuth 2 protocol client.

    :param session: Requests session object to communicate with
                    authorization server.
    :param client_id: Client ID, which you get from client registration.
    :param client_secret: Client Secret, which you get from registration.
    :param token_endpoint_auth_method: client authentication method for
        token endpoint.
    :param revocation_endpoint_auth_method: client authentication method for
        revocation endpoint.
    :param scope: Scope that you needed to access user resources.
    :param state: Shared secret to prevent CSRF attack.
    :param redirect_uri: Redirect URI you registered as callback.
    :param code_challenge_method: PKCE method name, only S256 is supported.
    :param token: A dict of token attributes such as ``access_token``,
        ``token_type`` and ``expires_at``.
    :param token_placement: The place to put token in HTTP request. Available
        values: "header", "body", "uri".
    :param update_token: A function for you to update token. It accept a
        :class:`OAuth2Token` as parameter.
    :param leeway: Time window in seconds before the actual expiration of the
        authentication token, that the token is considered expired and will
        be refreshed.
    )Úresponse_modeÚnonceÚpromptÚ
login_hintNc                 ó¶  — || _         || _        || _        || _        |€|rd}nd}|| _        |€|rd}nd}|| _        || _        || _        |	| _        | j                  |
|| «      | _
        || _        |j                  dd «      }|rt        d«      ‚|| _        t        «       t        «       t        «       t        «       t        «       dœ| _        i | _        || _        y )NÚclient_secret_basicÚnoneÚtoken_updaterz<update token has been redesigned, checkout the documentation)Úaccess_token_responseÚrefresh_token_requestÚrefresh_token_responseÚrevoke_token_requestÚintrospect_token_request)ÚsessionÚ	client_idÚclient_secretÚstateÚtoken_endpoint_auth_methodÚrevocation_endpoint_auth_methodÚscopeÚredirect_uriÚcode_challenge_methodÚtoken_auth_classÚ
token_authÚupdate_tokenÚpopÚ
ValueErrorÚmetadataÚsetÚcompliance_hookÚ_auth_methodsÚleeway)Úselfr   r    r!   r#   r$   r%   r"   r&   r'   ÚtokenÚtoken_placementr*   r1   r-   r   s                   úM/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth2/client.pyÚ__init__zOAuth2Client.__init__5   sò   € ð" ˆŒØ"ˆŒØ*ˆÔØˆŒ
à%Ð-ÙØ-BÑ*à-3Ð*à*DˆÔ'à*Ð2ÙØ2GÑ/à28Ð/à/NˆÔ,àˆŒ
Ø(ˆÔØ%:ˆÔ"à×/Ñ/°°ÈÓMˆŒØ(ˆÔà Ÿ™ _°dÓ;ˆÙÜØNóð ð !ˆŒô &)£UÜ%(£UÜ&)£eÜ$'£EÜ(+«ñ 
ˆÔð  ˆÔàˆ�ó    c                 ó‚   — t        |t        «      r|d   | j                  |d   <   y|| j                  |j                  <   y)zmExtend client authenticate for token endpoint.

        :param auth: an instance to sign the request
        r   r   N)Ú
isinstanceÚtupler0   Úname)r2   Úauths     r5   Úregister_client_auth_methodz(OAuth2Client.register_client_auth_methodu   s:   € ô
 �dœEÔ"Ø*.¨q©'ˆD×Ñ˜t A™wÒ'à,0ˆD×Ñ˜tŸy™yÒ)r7   c                 ó¬   — t        |t        «      r|| j                  v r| j                  |   }| j                  | j                  | j
                  |¬«      S )N)r    r!   Úauth_method)r9   Ústrr0   Úclient_auth_classr    r!   )r2   r?   s     r5   Úclient_authzOAuth2Client.client_auth   sT   € Ü�k¤3Ô'¨K¸4×;MÑ;MÑ,MØ×,Ñ,¨[Ñ9ˆKØ×%Ñ%Ø—n‘nØ×,Ñ,Ø#ð &ó 
ð 	
r7   c                 ó.   — | j                   j                  S ©N)r)   r3   ©r2   s    r5   r3   zOAuth2Client.tokenˆ   s   € à�‰×$Ñ$Ð$r7   c                 ó:   — | j                   j                  |«       y rD   )r)   Ú	set_token)r2   r3   s     r5   r3   zOAuth2Client.tokenŒ   s   € à�‰×!Ñ! %Õ(r7   c                 óÒ  — |€
t        «       }| j                  j                  dd«      }|j                  d|«      }d|vr| j                  |d<   d|vr| j
                  |d<   |r1|dk(  r,| j                  dk(  rt        |«      |d<   | j                  |d<   | j                  D ](  }||vsŒ|| j                  v sŒ| j                  |   ||<   Œ* t        |f| j                  ||dœ|¤Ž}||fS )	a   Generate an authorization URL and state.

        :param url: Authorization endpoint url, must be HTTPS.
        :param state: An optional state string for CSRF protection. If not
                      given it will be generated for you.
        :param code_verifier: An optional code_verifier for code challenge.
        :param kwargs: Extra parameters to include.
        :return: authorization_url, state
        Úresponse_typeÚcoder&   r%   ÚS256Úcode_challenger'   )r    rI   r"   )r   r-   Úgetr+   r&   r%   r'   r   ÚEXTRA_AUTHORIZE_PARAMSr   r    )r2   Úurlr"   Úcode_verifierÚkwargsrI   ÚkÚuris           r5   Úcreate_authorization_urlz%OAuth2Client.create_authorization_url�   s  € ð ˆ=Ü"Ó$ˆEàŸ™×)Ñ)¨/¸6ÓBˆØŸ
™
 ?°MÓBˆØ Ñ'Ø%)×%6Ñ%6ˆF�>Ñ"Ø˜&Ñ Ø"Ÿj™jˆF�7‰Oñ Ø Ò'Ø×*Ñ*¨fÒ4ä'AÀ-Ó'PˆFÐ#Ñ$Ø.2×.HÑ.HˆFÐ*Ñ+à×,Ñ,ò 	-ˆAØ˜Š 1¨¯©Ò#5Ø ŸM™M¨!Ñ,��q’	ð	-ô  Øð
à—n‘nØ'Øñ	
ð
 ñ
ˆð �EˆzÐr7   c                 ó   — |xs | j                   }|j                  dd«      }	|	rd|	v r| j                  |	|«      S | j                  |«      }
|	rd|	v rd}t	        |	|¬«      }|d   |d<   |€| j
                  j                  d«      }|€t        |«      }|| j
                  d<    | j                  ||fi |¤Ž}|€| j                  | j                  «      }|€t        }|€| j
                  j                  d	«      } | j                  |f||||d
œ|
¤ŽS )a«  Generic method for fetching an access token from the token endpoint.

        :param url: Access Token endpoint URL, if not configured,
                    ``authorization_response`` is used to extract token from
                    its fragment (implicit way).
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param method: The HTTP method used to make the request. Defaults
                       to POST, but may also be GET. Other methods should
                       be added as needed.
        :param headers: Dict to default request headers with.
        :param auth: An auth tuple or method as accepted by requests.
        :param grant_type: Use specified grant_type to fetch token.
        :param state: Optional "state" value to fetch token.
        :return: A :class:`OAuth2Token` object (a dict too).
        Úauthorization_responseNú#zcode=Úauthorization_code)r"   rJ   Ú
grant_typeÚtoken_endpoint)Úbodyr<   ÚmethodÚheaders)r"   r+   Útoken_from_fragmentÚ_extract_session_request_paramsr	   r-   rM   Ú_guess_grant_typeÚ_prepare_token_endpoint_bodyrB   r#   ÚDEFAULT_HEADERSÚ_fetch_token)r2   rO   r[   r\   r]   r<   rY   r"   rQ   rV   Úsession_kwargsÚparamss               r5   Úfetch_tokenzOAuth2Client.fetch_token¹   s@  € ð6 Ò#˜Ÿ™ˆà!'§¡Ð,DÀdÓ!KÐÙ! cÐ-CÑ&CØ×+Ñ+Ð,BÀEÓJÐJà×=Ñ=¸fÓEˆá! gÐ1GÑ&GØ-ˆJÜ6Ø&ØôˆFð $ F™^ˆF�6‰NàÐØŸ™×*Ñ*¨<Ó8ˆJàÐÜ*¨6Ó2ˆJØ*4ˆD�M‰M˜,Ñ'à0ˆt×0Ñ0°°zÑLÀVÑLˆàˆ<Ø×#Ñ# D×$CÑ$CÓDˆDàˆ?Ü%ˆGàˆ;Ø—-‘-×#Ñ#Ð$4Ó5ˆCà ˆt× Ñ Øð
Ø ¨f¸gñ
ØIWñ
ð 	
r7   c                 ó~   — t        ||«      }d|v r%| j                  |d   |j                  d«      ¬«      ‚|| _        |S )NÚerrorÚerror_description©rh   Údescription)r
   Úoauth_error_classrM   r3   )r2   rV   r"   r3   s       r5   r^   z OAuth2Client.token_from_fragmentú   sP   € Ü'Ð(>ÀÓFˆØ�eÑØ×(Ñ(Ø˜G‘n°%·)±)Ð<OÓ2Pð )ó ð ð ˆŒ
Øˆr7   c                 óÒ  — | j                  |«      }|xs | j                  j                  d«      }d|vr| j                  r| j                  |d<   t	        d|fd|i|¤Ž}|€t
        j                  «       }|€| j                  j                  d«      }| j                  d   D ]  } ||||«      \  }}}Œ |€| j                  | j                  «      } | j                  |f||||dœ|¤ŽS )a	  Fetch a new access token using a refresh token.

        :param url: Refresh Token endpoint, must be HTTPS.
        :param refresh_token: The refresh_token to use.
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by requests.
        :param headers: Dict to default request headers with.
        :return: A :class:`OAuth2Token` object (a dict too).
        Úrefresh_tokenr%   rZ   r   )rn   r[   r]   r<   )r_   r3   rM   r%   r   rb   Úcopyr-   r/   rB   r#   Ú_refresh_token)	r2   rO   rn   r[   r<   r]   rQ   rd   Úhooks	            r5   rn   zOAuth2Client.refresh_token  s  € ð ×=Ñ=¸fÓEˆØ%ÒH¨¯©¯©¸Ó)HˆØ˜&Ñ  T§Z¢ZØ"Ÿj™jˆF�7‰OÜ$Ø˜Tñ
Ø1>ð
ØBHñ
ˆð ˆ?Ü%×*Ñ*Ó,ˆGàˆ;Ø—-‘-×#Ñ#Ð$4Ó5ˆCà×(Ñ(Ð)@ÑAò 	:ˆDÙ!% c¨7°DÓ!9ÑˆC�™$ð	:ð ˆ<Ø×#Ñ# D×$CÑ$CÓDˆDà"ˆt×"Ñ"Øð
à'ØØØñ
ð ñ
ð 	
r7   c                 óŽ  — |€| j                   }|j                  | j                  ¬«      sy|j                  d«      }| j                  j                  d«      }|r|r| j                  ||¬«       y| j                  j                  d«      dk(  r8|d   }| j                  |d¬	«      }| j                  r| j                  ||¬
«       yy )N)r1   Trn   rZ   ©rn   rY   Úclient_credentialsÚaccess_token)rY   )ru   )r3   Ú
is_expiredr1   rM   r-   rn   rf   r*   )r2   r3   rn   rO   ru   Ú	new_tokens         r5   Úensure_active_tokenz OAuth2Client.ensure_active_token-  sÃ   € Øˆ=Ø—J‘JˆEØ×Ñ t§{¡{ÐÔ3ØØŸ	™	 /Ó2ˆØ�m‰m×ÑÐ 0Ó1ˆÙ™SØ×Ñ˜s°-ÐÔ@ØØ�]‰]×Ñ˜|Ó,Ð0DÒDØ  Ñ0ˆLØ×(Ñ(¨Ð9MÐ(ÓNˆIØ× Ò Ø×!Ñ! )¸,Ð!ÔGØð Er7   c           	      óp   — |€| j                  | j                  «      } | j                  d|f|||||dœ|¤ŽS )a¶  Revoke token method defined via `RFC7009`_.

        :param url: Revoke Token endpoint, must be HTTPS.
        :param token: The token to be revoked.
        :param token_type_hint: The type of the token that to be revoked.
                                It can be "access_token" or "refresh_token".
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by requests.
        :param headers: Dict to default request headers with.
        :return: Revocation Response

        .. _`RFC7009`: https://tools.ietf.org/html/rfc7009
        r   ©r3   Útoken_type_hintr[   r<   r]   )rB   r$   Ú_handle_token_hint©r2   rO   r3   r{   r[   r<   r]   rQ   s           r5   Úrevoke_tokenzOAuth2Client.revoke_token>  sZ   € ð0 ˆ<Ø×#Ñ# D×$HÑ$HÓIˆDØ&ˆt×&Ñ&Ø"Øð	
ð Ø+ØØØñ	
ð ñ	
ð 		
r7   c           	      óp   — |€| j                  | j                  «      } | j                  d|f|||||dœ|¤ŽS )aÛ  Implementation of OAuth 2.0 Token Introspection defined via `RFC7662`_.

        :param url: Introspection Endpoint, must be HTTPS.
        :param token: The token to be introspected.
        :param token_type_hint: The type of the token that to be revoked.
                                It can be "access_token" or "refresh_token".
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by requests.
        :param headers: Dict to default request headers with.
        :return: Introspection Response

        .. _`RFC7662`: https://tools.ietf.org/html/rfc7662
        r   rz   )rB   r#   r|   r}   s           r5   Úintrospect_tokenzOAuth2Client.introspect_tokenc  sZ   € ð0 ˆ<Ø×#Ñ# D×$CÑ$CÓDˆDØ&ˆt×&Ñ&Ø&Øð	
ð Ø+ØØØñ	
ð ñ	
ð 		
r7   c                 óà   — |dk(  r&| j                   j                  j                  |«       y|| j                  vrt	        d|| j                  «      ‚| j                  |   j                  |«       y)aè  Register a hook for request/response tweaking.

        Available hooks are:

        * access_token_response: invoked before token parsing.
        * refresh_token_request: invoked before refreshing token.
        * refresh_token_response: invoked before refresh token parsing.
        * protected_request: invoked before making a request.
        * revoke_token_request: invoked before revoking a token.
        * introspect_token_request: invoked before introspecting a token.
        Úprotected_requestNzHook type %s is not in %s.)r)   ÚhooksÚaddr/   r,   )r2   Ú	hook_typerq   s      r5   Úregister_compliance_hookz%OAuth2Client.register_compliance_hookˆ  sk   € ð Ð+Ò+Ø�O‰O×!Ñ!×%Ñ% dÔ+Øà˜D×0Ñ0Ñ0ÜØ,¨i¸×9MÑ9Móð ð 	×Ñ˜YÑ'×+Ñ+¨DÕ1r7   c                 óØ   — |j                   dk\  r|j                  «        |j                  «       }d|v r%| j                  |d   |j	                  d«      ¬«      ‚|| _        | j
                  S )Niô  rh   ri   rj   )Ústatus_codeÚraise_for_statusÚjsonrl   rM   r3   )r2   Úrespr3   s      r5   Úparse_response_tokenz!OAuth2Client.parse_response_tokenž  sm   € Ø×Ñ˜sÒ"Ø×!Ñ!Ô#à—	‘	“ˆØ�eÑØ×(Ñ(Ø˜G‘n°%·)±)Ð<OÓ2Pð )ó ð ð ˆŒ
Ø�z‰zÐr7   c                 ó‚  — |j                  «       dk(  r4 | j                  j                  |ft        t	        |«      «      ||dœ|¤Ž}nLd|v rdj                  ||g«      }ndj                  ||g«      } | j                  j                  ||f||dœ|¤Ž}| j                  d   D ]
  } ||«      }Œ | j                  |«      S )NÚPOST©Údatar]   r<   ú?ú&)r]   r<   r   )	Úupperr   ÚpostÚdictr   ÚjoinÚrequestr/   rŒ   )	r2   rO   r[   r]   r<   r\   rQ   r‹   rq   s	            r5   rc   zOAuth2Client._fetch_tokenª  sÜ   € ð �<‰<‹>˜VÒ#Ø$�4—<‘<×$Ñ$ØðÜœz¨$Ó/Ó0¸'ÈñØPVñ‰Dð �c‰zØ—h‘h  T˜{Ó+‘à—h‘h  T˜{Ó+�Ø'�4—<‘<×'Ñ'Ø˜ðØ%,°4ñØ;AñˆDð ×(Ñ(Ð)@ÑAò 	ˆDÙ˜“:‰Dð	ð ×(Ñ(¨Ó.Ð.r7   c                 ó,  —  | j                   |f|||dœ|¤Ž}| j                  d   D ]
  } ||«      }Œ | j                  |«      }	d|	vr|| j                  d<   t	        | j
                  «      r| j                  | j                  |¬«       | j                  S )N)r[   r<   r]   r   rn   rs   )Ú
_http_postr/   rŒ   r3   Úcallabler*   )
r2   rO   rn   r[   r]   r<   rQ   r‹   rq   r3   s
             r5   rp   zOAuth2Client._refresh_token¿  s�   € ð ˆt�‰˜sÐT¨°DÀ'ÑTÈVÑTˆà×(Ñ(Ð)AÑBò 	ˆDÙ˜“:‰Dð	ð ×)Ñ)¨$Ó/ˆØ %Ñ'Ø*7ˆD�J‰J�Ñ'ä�D×%Ñ%Ô&Ø×Ñ˜dŸj™j¸ÐÔFà�z‰zÐr7   c                 ó†  — |€D| j                   r8| j                   j                  d«      xs | j                   j                  d«      }|€d}t        ||||«      \  }}| j                  |   D ]  }	 |	|||«      \  }}}Œ |€| j	                  | j
                  «      }| j                  |«      }
 | j                  ||f||dœ|
¤ŽS )Nrn   ru   Ú )r<   r]   )r3   rM   r   r/   rB   r$   r_   r™   )r2   rq   rO   r3   r{   r[   r<   r]   rQ   r/   rd   s              r5   r|   zOAuth2Client._handle_token_hintÐ  sÓ   € ð ˆ=˜TŸZšZØ—J‘J—N‘N ?Ó3ÒU°t·z±z·~±~ÀnÓ7UˆEàˆ<ØˆDä4Ø�? D¨'ó
‰ˆˆgð  $×3Ñ3°DÑ9ò 	EˆOÙ!0°°g¸tÓ!DÑˆC�™$ð	Eð ˆ<Ø×#Ñ# D×$HÑ$HÓIˆDà×=Ñ=¸fÓEˆØˆt�‰˜s DÐW¨t¸WÑWÈÑWÐWr7   c                 ó¤   — |dk(  r d|vr| j                   |d<   t        ||fi |¤ŽS d|vr| j                  r| j                  |d<   t        ||fi |¤ŽS )NrX   r&   r%   )r&   r   r%   )r2   r[   rY   rQ   s       r5   ra   z)OAuth2Client._prepare_token_endpoint_bodyî  sb   € ØÐ-Ò-Ø VÑ+Ø)-×):Ñ):��~Ñ&Ü(¨°TÑD¸VÑDÐDà˜&Ñ  T§Z¢ZØ"Ÿj™jˆF�7‰OÜ$ Z°Ñ@¸Ñ@Ð@r7   c                 ó^   — i }| j                   D ]  }||v sŒ|j                  |«      ||<   Œ |S )zDExtract parameters for session object from the passing ``**kwargs``.)ÚSESSION_REQUEST_PARAMSr+   )r2   rQ   ÚrvrR   s       r5   r_   z,OAuth2Client._extract_session_request_paramsø  s;   € àˆØ×,Ñ,ò 	&ˆAØ�FŠ{ØŸ
™
 1›��1’ð	&ð ˆ	r7   c                 óh   —  | j                   j                  |ft        t        |«      «      ||dœ|¤ŽS )Nr�   )r   r”   r•   r   )r2   rO   r[   r<   r]   rQ   s         r5   r™   zOAuth2Client._http_post   s<   € Ø ˆt�|‰|× Ñ Øð
Üœ: dÓ+Ó,°gÀDñ
ØLRñ
ð 	
r7   c                 ó   — | ` y rD   )r   rE   s    r5   Ú__del__zOAuth2Client.__del__  s   € Ø‰Lr7   )NNNNNNNNNÚheaderNé<   )NN)Nrœ   rŽ   NNNNrD   )NNrœ   NN)NNNNN)rœ   NNrŽ   )Nrœ   NN)NNN)"Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   rA   r   r(   r   rl   rN   rŸ   r6   r=   rB   Úpropertyr3   ÚsetterrT   rf   r^   rn   rx   r~   r€   r†   rŒ   rc   rp   r|   ra   r_   r™   r£   © r7   r5   r   r      s>  „ ñð2 #ÐØ ÐØ#ÐàOÐØÐð
 ØØ#'Ø(,ØØØØ"ØØ ØØó>ò@1ò
ð ñ%ó ð%ð ‡\�\ñ)ó ð)ó'ðV ØØØØØØó?
óBð IMó(
óTð( ØØØØó#
ðP ØØØØó#
òJ2ò,
ð =Có/ð, DHóð* ØØØØóXò<Aòó
ó
r7   r   c                 ó2   — d| v rd}|S d| v rd| v rd}|S d}|S )NrJ   rX   ÚusernameÚpasswordrt   r¬   )rQ   rY   s     r5   r`   r`   	  sB   € Ø�ÑØ)ˆ
ð
 Ðð	 
�vÑ	 *°Ñ"6Øˆ
ð Ðð *ˆ
ØÐr7   N)Úauthlib.common.securityr   Úauthlib.common.urlsr   r<   r   r   Úbaser   Úrfc6749.parametersr	   r
   r   r   Úrfc7009r   Úrfc7636r   rb   r   r`   r¬   r7   r5   ú<module>r¶      sG   ðÝ 2Ý *å Ý Ý Ý AÝ 7Ý 1Ý 5Ý 1Ý /ð !ØEñ€÷rñ rójr7   