Ë
    ”ÂiZ
  ã                   óV   — d dl mZ d dlmZ d dlmZ ddlmZ ddlm	Z	  G d„ de	«      Z
y	)
é    )ÚContinueIteration)ÚInvalidTokenError)ÚJWTBearerTokenValidatoré   )ÚUnsupportedTokenTypeError)ÚRevocationEndpointc                   ó0   ‡ — e Zd ZdZdˆ fd„	Zd„ Zd„ Zˆ xZS )ÚJWTRevocationEndpointaw  JWTRevocationEndpoint inherits from `RFC7009`_
    :class:`~authlib.oauth2.rfc7009.RevocationEndpoint`.

    The JWT access tokens cannot be revoked.
    If the submitted token is a JWT access token, then revocation returns
    a `invalid_token_error`.

    :param issuer: The issuer identifier.

    :param \\*\\*kwargs: Other parameters are inherited from
        :class:`~authlib.oauth2.rfc7009.RevocationEndpoint`.

    Plain text access tokens and other kind of tokens such as refresh_tokens
    will be ignored by this endpoint and passed to the next revocation endpoint::

        class MyJWTAccessTokenRevocationEndpoint(JWTRevocationEndpoint):
            def get_jwks(self): ...


        # endpoint dedicated to JWT access token revokation
        authorization_server.register_endpoint(
            MyJWTAccessTokenRevocationEndpoint(
                issuer="https://authorization-server.example.org",
            )
        )

        # another endpoint dedicated to refresh token revokation
        authorization_server.register_endpoint(MyRefreshTokenRevocationEndpoint)

    .. _RFC7009: https://tools.ietf.org/html/rfc7009
    c                 ó6   •— t        ‰| �  |d|i|¤Ž || _        y )NÚserver)ÚsuperÚ__init__Úissuer)Úselfr   r   ÚargsÚkwargsÚ	__class__s        €úY/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth2/rfc9068/revocation.pyr   zJWTRevocationEndpoint.__init__*   s!   ø€ Ü‰Ñ˜$Ð8 vÐ8°Ò8Øˆ�ó    c                 óN  — | j                  ||«       |j                  j                  d«      dvr
t        «       ‚t	        | j
                  d¬«      }| j                  |_        	 |j                  |j                  d   «       t        «       ‚# t        $ r}t        «       |‚d}~ww xY w)Ú Útoken_type_hint)Úaccess_tokenNN)r   Úresource_serverÚtoken)
Úcheck_paramsÚformÚgetr   r   r   Úget_jwksÚauthenticate_tokenr   r   )r   ÚrequestÚclientÚ	validatorÚexcs        r   r    z(JWTRevocationEndpoint.authenticate_token.   s—   € à×Ñ˜' 6Ô*ð �<‰<×ÑÐ-Ó.Ð6LÑLÜ#Ó%Ð%ä+°4·;±;ÐPTÔUˆ	Ø!Ÿ]™]ˆ	Ôð	/Ø×(Ñ(¨¯©°gÑ)>Ô?ô (Ó)Ð)øô	 !ò 	/Ü#Ó%¨3Ð.ûð	/ús   Á#B Â	B$ÂBÂB$c                 ó   — t        «       ‚)zÕReturn the JWKs that will be used to check the JWT access token signature.
        Developers MUST re-implement this method::

            def get_jwks(self):
                return load_jwks("jwks.json")
        )ÚNotImplementedError)r   s    r   r   zJWTRevocationEndpoint.get_jwksC   s   € ô "Ó#Ð#r   )N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r    r   Ú__classcell__)r   s   @r   r
   r
   	   s   ø„ ñõ@ò*ö*$r   r
   N)Úauthlib.common.errorsr   Úauthlib.oauth2.rfc6750.errorsr   Ú&authlib.oauth2.rfc9068.token_validatorr   Úrfc6749r   Úrfc7009r   r
   © r   r   ú<module>r2      s#   ðÝ 3Ý ;Ý Jå /Ý (ôA$Ð.õ A$r   