Ë
    ”Âi74  ã                   ó°   — d dl mZ d dlmZ ddlmZ ddlmZ ddlmZ ddlm	Z	 ddlm
Z
 dd	lmZ dd
lmZ ddlmZ ddlmZ ddlmZ  G d„ de«      Zd„ Zy)é    )ÚContinueIteration)Ú	deprecateé   )ÚClientAuthentication)ÚInvalidScopeError)ÚOAuth2Error)ÚUnsupportedGrantTypeError)ÚUnsupportedResponseTypeError)ÚHookable)Úhooked)ÚJsonRequest)ÚOAuth2Request)Úscope_to_listc                   óÞ   ‡ — e Zd ZdZdˆ fd„	Zd„ Zd„ Z	 	 	 	 dd„Zd„ Zdd„Z	d„ Z
d	„ Zd
„ Zd„ Zdefd„Zdefd„Zd„ Zd„ Zdd„Zd„ Zed„ «       Zdd„Zd„ Zdd„Zedd„«       Zdd„Zd„ Zˆ xZS )ÚAuthorizationServerz¬Authorization server that handles Authorization Endpoint and Token
    Endpoint.

    :param scopes_supported: A list of supported scopes by this authorization server.
    c                 ó„   •— t         ‰| �  «        || _        i | _        d | _        g | _        g | _        i | _        g | _        y ©N)	ÚsuperÚ__init__Úscopes_supportedÚ_token_generatorsÚ_client_authÚ_authorization_grantsÚ_token_grantsÚ
_endpointsÚ_extensions)Úselfr   Ú	__class__s     €úc/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth2/rfc6749/authorization_server.pyr   zAuthorizationServer.__init__   sE   ø€ Ü‰ÑÔØ 0ˆÔØ!#ˆÔØ ˆÔØ%'ˆÔ"ØˆÔØˆŒØˆÕó    c                 ó   — t        «       ‚)z¦Query OAuth client by client_id. The client model class MUST
        implement the methods described by
        :class:`~authlib.oauth2.rfc6749.ClientMixin`.
        ©ÚNotImplementedError)r   Ú	client_ids     r   Úquery_clientz AuthorizationServer.query_client!   s   € ô
 "Ó#Ð#r    c                 ó   — t        «       ‚)z:Define function to save the generated token into database.r"   )r   ÚtokenÚrequests      r   Ú
save_tokenzAuthorizationServer.save_token(   ó   € ä!Ó#Ð#r    c                 ó¨   — | j                   j                  |«      }|s| j                   j                  d«      }|st        d«      ‚ |||||||¬«      S )a�  Generate the token dict.

        :param grant_type: current requested grant_type.
        :param client: the client that making the request.
        :param user: current authorized user.
        :param expires_in: if provided, use this value as expires_in.
        :param scope: current requested scope.
        :param include_refresh_token: should refresh_token be included.
        :return: Token dict
        ÚdefaultzNo configured token generator)Ú
grant_typeÚclientÚuserÚscopeÚ
expires_inÚinclude_refresh_token)r   ÚgetÚRuntimeError)r   r-   r.   r/   r0   r1   r2   Úfuncs           r   Úgenerate_tokenz"AuthorizationServer.generate_token,   sa   € ð( ×%Ñ%×)Ñ)¨*Ó5ˆÙà×)Ñ)×-Ñ-¨iÓ8ˆDÙÜÐ>Ó?Ð?áØ!ØØØØ!Ø"7ô
ð 	
r    c                 ó"   — || j                   |<   y)ay  Register a function as token generator for the given ``grant_type``.
        Developers MUST register a default token generator with a special
        ``grant_type=default``::

            def generate_bearer_token(
                grant_type,
                client,
                user=None,
                scope=None,
                expires_in=None,
                include_refresh_token=True,
            ):
                token = {"token_type": "Bearer", "access_token": ...}
                if include_refresh_token:
                    token["refresh_token"] = ...
                ...
                return token


            authorization_server.register_token_generator(
                "default", generate_bearer_token
            )

        If you register a generator for a certain grant type, that generator will only works
        for the given grant type::

            authorization_server.register_token_generator(
                "client_credentials",
                generate_bearer_token,
            )

        :param grant_type: string name of the grant type
        :param func: a function to generate token
        N)r   )r   r-   r5   s      r   Úregister_token_generatorz,AuthorizationServer.register_token_generatorP   s   € ðF .2ˆ×Ñ˜zÒ*r    c                 óŒ   — | j                   €&| j                  rt        | j                  «      | _         | j                  |||«      S )z’Authenticate client via HTTP request information with the given
        methods, such as ``client_secret_basic``, ``client_secret_post``.
        )r   r%   r   )r   r(   ÚmethodsÚendpoints       r   Úauthenticate_clientz'AuthorizationServer.authenticate_clientu   s@   € ð ×ÑÐ$¨×):Ò):Ü 4°T×5FÑ5FÓ GˆDÔØ× Ñ  ¨'°8Ó<Ð<r    c                 ó    — | j                   €&| j                  rt        | j                  «      | _         | j                   j                  ||«       y)at  Add more client auth method. The default methods are:

        * none: The client is a public client and does not have a client secret
        * client_secret_post: The client uses the HTTP POST parameters
        * client_secret_basic: The client uses HTTP Basic

        :param method: Name of the Auth method
        :param func: Function to authenticate the client

        The auth method accept two parameters: ``query_client`` and ``request``,
        an example for this method::

            def authenticate_client_via_custom(query_client, request):
                client_id = request.headers["X-Client-Id"]
                client = query_client(client_id)
                do_some_validation(client)
                return client


            authorization_server.register_client_auth_method(
                "custom", authenticate_client_via_custom
            )
        N)r   r%   r   Úregister)r   Úmethodr5   s      r   Úregister_client_auth_methodz/AuthorizationServer.register_client_auth_method}   sA   € ð0 ×ÑÐ$¨×):Ò):Ü 4°T×5FÑ5FÓ GˆDÔà×Ñ×"Ñ" 6¨4Õ0r    c                 óF   — | j                   j                   || «      «       y r   )r   Úappend)r   Ú	extensions     r   Úregister_extensionz&AuthorizationServer.register_extensionš   s   € Ø×Ñ×Ñ¡	¨$£Õ0r    c                  ó   — y)zFReturn a URI for the given error, framework may implement this method.N© ©r   r(   Úerrors      r   Úget_error_uriz!AuthorizationServer.get_error_uri�   s   € àr    c                 ó   — t        «       ‚)z]Framework integration can re-implement this method to support
        signal system.
        r"   )r   ÚnameÚargsÚkwargss       r   Úsend_signalzAuthorizationServer.send_signal¡   s   € ô "Ó#Ð#r    Úreturnc                 ó   — t        «       ‚)zàThis method MUST be implemented in framework integrations. It is
        used to create an OAuth2Request instance.

        :param request: the "request" instance in framework
        :return: OAuth2Request instance
        r"   ©r   r(   s     r   Úcreate_oauth2_requestz)AuthorizationServer.create_oauth2_request§   ó   € ô "Ó#Ð#r    c                 ó   — t        «       ‚)zÜThis method MUST be implemented in framework integrations. It is
        used to create an HttpRequest instance.

        :param request: the "request" instance in framework
        :return: HttpRequest instance
        r"   rQ   s     r   Úcreate_json_requestz'AuthorizationServer.create_json_request°   rS   r    c                 ó   — t        «       ‚)z=Return HTTP response. Framework MUST implement this function.r"   )r   ÚstatusÚbodyÚheaderss       r   Úhandle_responsez#AuthorizationServer.handle_response¹   r*   r    c                 ó¨   — |rP| j                   rCt        t        |«      «      }t        | j                   «      j                  |«      s
t	        «       ‚yyy)zŠValidate if requested scope is supported by Authorization Server.
        Developers CAN re-write this method to meet your needs.
        N)r   Úsetr   Ú
issupersetr   )r   r0   Úscopess      r   Úvalidate_requested_scopez,AuthorizationServer.validate_requested_scope½   sM   € ñ �T×*Ò*Üœ uÓ-Ó.ˆFÜ�t×,Ñ,Ó-×8Ñ8¸Ô@Ü'Ó)Ð)ð Að +ˆ5r    c                 óª   — t        |d«      r| j                  j                  ||f«       t        |d«      r| j                  j                  ||f«       yy)aÿ  Register a grant class into the endpoint registry. Developers
        can implement the grants in ``authlib.oauth2.rfc6749.grants`` and
        register with this method::

            class AuthorizationCodeGrant(grants.AuthorizationCodeGrant):
                def authenticate_user(self, credential):
                    # ...

            authorization_server.register_grant(AuthorizationCodeGrant)

        :param grant_cls: a grant class.
        :param extensions: extensions for the grant class.
        Úcheck_authorization_endpointÚcheck_token_endpointN)Úhasattrr   rB   r   )r   Ú	grant_clsÚ
extensionss      r   Úregister_grantz"AuthorizationServer.register_grantÆ   sQ   € ô �9Ð<Ô=Ø×&Ñ&×-Ñ-¨y¸*Ð.EÔFÜ�9Ð4Ô5Ø×Ñ×%Ñ% y°*Ð&=Õ>ð 6r    c                 ó²   — t        |t        «      r	 || «      }n| |_        | j                  j	                  |j
                  g «      }|j                  |«       y)zÚAdd extra endpoint to authorization server. e.g.
        RevocationEndpoint::

            authorization_server.register_endpoint(RevocationEndpoint)

        :param endpoint_cls: A endpoint class or instance.
        N)Ú
isinstanceÚtypeÚserverr   Ú
setdefaultÚENDPOINT_NAMErB   )r   r;   Ú	endpointss      r   Úregister_endpointz%AuthorizationServer.register_endpointÙ   sH   € ô �h¤Ô%Ù “~‰Hà"ˆHŒOà—O‘O×.Ñ.¨x×/EÑ/EÀrÓJˆ	Ø×Ñ˜Õ"r    c                 ó  — | j                   D ]&  \  }}|j                  |«      sŒt        |||| «      c S  t        d|j                  j
                  › d�|j                  j
                  |j                  j                  ¬«      ‚)z‹Find the authorization grant for current request.

        :param request: OAuth2Request instance.
        :return: grant instance
        zThe response type 'z!' is not supported by the server.)Úredirect_uri)r   ra   Ú_create_grantr
   ÚpayloadÚresponse_typerp   ©r   r(   rd   re   s       r   Úget_authorization_grantz+AuthorizationServer.get_authorization_granté   s€   € ð &*×%?Ñ%?ò 	KÑ!ˆI�zØ×5Ñ5°gÕ>Ü$ Y°
¸GÀTÓJÒJð	Kô +Ø! '§/¡/×"?Ñ"?Ð!@Ð@aÐbØ�O‰O×)Ñ)Ø Ÿ™×5Ñ5ô
ð 	
r    c                 óö   — | j                  |«      }	 ||_        | j                  |«      }|j                  |«       |j	                  «        |S # t
        $ r!}|j                  j                  |_        ‚ d}~ww xY w)z“Validate current HTTP request for authorization page. This page
        is designed for resource owner to grant or deny the authorization.
        N)rR   r/   ru   Ú&validate_no_multiple_request_parameterÚvalidate_consent_requestr   rr   Ústate)r   r(   Úend_userÚgrantrH   s        r   Úget_consent_grantz%AuthorizationServer.get_consent_grantú   sy   € ð ×,Ñ,¨WÓ5ˆð	Ø#ˆGŒLà×0Ñ0°Ó9ˆEØ×8Ñ8¸ÔAØ×*Ñ*Ô,ð ˆøô ò 	ð "Ÿ/™/×/Ñ/ˆEŒKØûð	ús   “9A Á	A8ÁA3Á3A8c                 óª   — | j                   D ]&  \  }}|j                  |«      sŒt        |||| «      c S  t        |j                  j
                  «      ‚)zƒFind the token grant for current request.

        :param request: OAuth2Request instance.
        :return: grant instance
        )r   rb   rq   r	   rr   r-   rt   s       r   Úget_token_grantz#AuthorizationServer.get_token_grant  sV   € ð &*×%7Ñ%7ò 	KÑ!ˆI�zØ×-Ñ-¨gÕ6Ü$ Y°
¸GÀTÓJÒJð	Kô (¨¯©×(BÑ(BÓCÐCr    c                 ó"  — || j                   vrt        d|› d�«      ‚| j                   |   }|D ]*  }|j                  |«      }	  | j                   ||«      Ž c S  y# t        $ r Y Œ9t
        $ r}| j                  ||«      cY d}~c S d}~ww xY w)z­Validate endpoint request and create endpoint response.

        :param name: Endpoint name
        :param request: HTTP request instance.
        :return: Response
        zThere is no 'z' endpoint.N)r   r4   Úcreate_endpoint_requestrZ   r   r   Úhandle_error_response)r   rK   r(   rm   r;   rH   s         r   Úcreate_endpoint_responsez,AuthorizationServer.create_endpoint_response  s£   € ð �t—‘Ñ&Ü ¨t¨f°KÐ@ÓAÐAà—O‘O DÑ)ˆ	Ø!ò 	BˆHØ×6Ñ6°wÓ?ˆGðBØ+�t×+Ñ+©X°gÓ->Ð?Ò?ñ	Bøô %ò ÙÜò BØ×1Ñ1°'¸5ÓA×AûðBús$   ÁAÁ	BÁ(BÁ0B	ÂBÂ	Bc                 ó  — t        |t        «      s| j                  |«      }|st        dd¬«       	 | j	                  |«      }	 |j                  «       }|j                  ||«      } | j                  |Ž }|j                  d|«       |S # t
        $ r7}|j                  j                  |_        | j                  ||«      cY d}~S d}~ww xY w# t        $ r7}|j                  j                  |_        | j                  ||«      }Y d}~Œ’d}~ww xY w)zõValidate authorization request and create authorization response.

        :param request: HTTP request instance.
        :param grant_user: if granted, it is resource owner. If denied,
            it is None.
        :returns: Response
        z,The 'grant' parameter will become mandatory.z1.8)ÚversionNÚafter_authorization_response)rh   r   rR   r   ru   r
   rr   ry   r�   Úvalidate_authorization_requestÚcreate_authorization_responserZ   r   Úexecute_hook)r   r(   Ú
grant_userr{   rH   rp   rL   Úresponses           r   r‡   z1AuthorizationServer.create_authorization_response.  s   € ô ˜'¤=Ô1Ø×0Ñ0°Ó9ˆGáÜÐDÈeÕTðBØ×4Ñ4°WÓ=�ð
	BØ ×?Ñ?ÓAˆLØ×6Ñ6°|ÀZÓPˆDØ+�t×+Ñ+¨TÐ2ˆHð
 	×ÑÐ9¸8ÔDØˆøô 0ò BØ%Ÿo™o×3Ñ3�”Ø×1Ñ1°'¸5ÓAÕAûðBûô ò 	BØ!Ÿ/™/×/Ñ/ˆEŒKØ×1Ñ1°'¸5ÓA�Hûð	Bús5   ²B	 Á1C Â		C	Â,CÂ>C	ÃC	Ã	DÃ-DÄDc                 óH  — | j                  |«      }	 | j                  |«      }	 |j	                  «        |j                  «       } | j                  |Ž S # t        $ r}| j                  ||«      cY d}~S d}~ww xY w# t        $ r}| j                  ||«      cY d}~S d}~ww xY w)ziValidate token request and create token response.

        :param request: HTTP request instance
        N)rR   r~   r	   r�   Úvalidate_token_requestÚcreate_token_responserZ   r   )r   r(   r{   rH   rL   s        r   r�   z)AuthorizationServer.create_token_responseM  s¤   € ð
 ×,Ñ,¨WÓ5ˆð	>Ø×(Ñ(¨Ó1ˆEð	>Ø×(Ñ(Ô*Ø×.Ñ.Ó0ˆDØ'�4×'Ñ'¨Ð.Ð.øô )ò 	>Ø×-Ñ-¨g°uÓ=Õ=ûð	>ûô ò 	>Ø×-Ñ-¨g°uÓ=Õ=ûð	>ús:   “A ¥.A< Á	A9ÁA4Á.A9Á4A9Á<	B!ÂBÂB!ÂB!c                 óL   —  | j                    || j                  ||«      «      Ž S r   )rZ   rI   rG   s      r   r�   z)AuthorizationServer.handle_error_response_  s'   € Ø#ˆt×#Ñ#¡U¨4×+=Ñ+=¸gÀuÓ+MÓ%NÐOÐOr    r   )NNNT)r'   )NN)NNN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r%   r)   r6   r8   r<   r@   rD   rI   rN   r   rR   r   rU   rZ   r_   rf   rn   r   ru   r|   r~   r‚   r‡   r�   r�   Ú__classcell__)r   s   @r   r   r      sº   ø„ ñõò$ò$ð ØØØ"ó"
òH#2óJ=ò1ò:1òò$ð$°ó $ð$¨kó $ò$ò*ó?ò&#ð  ñ
ó ð
ó ò*	DóBð( òó ðó<>ö$Pr    r   c                 ó:   —  | ||«      }|r|D ]
  } ||«       Œ |S r   rF   )rd   re   r(   rj   r{   Úexts         r   rq   rq   c  s,   € Ù�g˜vÓ&€EÙØò 	ˆCÙ��Jð	à€Lr    N)Úauthlib.common.errorsr   Úauthlib.deprecater   r<   r   Úerrorsr   r   r	   r
   Úhooksr   r   Úrequestsr   r   Úutilr   r   rq   rF   r    r   ú<module>rœ      s?   ðÝ 3Ý 'å 5Ý %Ý Ý -Ý 0Ý Ý Ý !Ý #Ý ôPP˜(ô PPóf
r    