Ë
    ”ÂiÑ  ã                   ór   — d Z ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddl	m
Z
 dd	lmZ  G d
„ de
«      Zy)zðauthlib.oauth2.rfc9068.token_validator.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Implementation of Validating JWT Access Tokens per `Section 4`_.

.. _`Section 7`: https://www.rfc-editor.org/rfc/rfc9068.html#name-validating-jwt-access-token
é    )Újwt)ÚDecodeError)Ú	JoseError)ÚInsufficientScopeError)ÚInvalidTokenError)ÚBearerTokenValidatoré   )ÚJWTAccessTokenClaimsc                   óH   ‡ — e Zd ZdZˆ fd„Zd„ Zdddefd„Zd„ Z	 d
d	„Z	ˆ xZ
S )ÚJWTBearerTokenValidatora  JWTBearerTokenValidator can protect your resource server endpoints.

    :param issuer: The issuer from which tokens will be accepted.
    :param resource_server: An identifier for the current resource server,
        which must appear in the JWT ``aud`` claim.

    Developers needs to implement the missing methods::

        class MyJWTBearerTokenValidator(JWTBearerTokenValidator):
            def get_jwks(self): ...


        require_oauth = ResourceProtector()
        require_oauth.register_token_validator(
            MyJWTBearerTokenValidator(
                issuer="https://authorization-server.example.org",
                resource_server="https://resource-server.example.org",
            )
        )

    You can then protect resources depending on the JWT `scope`, `groups`,
    `roles` or `entitlements` claims::

        @require_oauth(
            scope="profile",
            groups="admins",
            roles="student",
            entitlements="captain",
        )
        def resource_endpoint(): ...
    c                 ó@   •— || _         || _        t        ‰| �  |i |¤Ž y ©N)ÚissuerÚresource_serverÚsuperÚ__init__)Úselfr   r   ÚargsÚkwargsÚ	__class__s        €ú^/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth2/rfc9068/token_validator.pyr   z JWTBearerTokenValidator.__init__4   s$   ø€ ØˆŒØ.ˆÔÜ‰Ñ˜$Ð) &Ó)ó    c                 ó   — t        «       ‚)az  Return the JWKs that will be used to check the JWT access token signature.
        Developers MUST re-implement this method. Typically the JWKs are statically
        stored in the resource server configuration, or dynamically downloaded and
        cached using :ref:`specs/rfc8414`::

            def get_jwks(self):
                if "jwks" in cache:
                    return cache.get("jwks")

                server_metadata = get_server_metadata(self.issuer)
                jwks_uri = server_metadata.get("jwks_uri")
                cache["jwks"] = requests.get(jwks_uri).json()
                return cache["jwks"]
        )ÚNotImplementedError)r   s    r   Úget_jwksz JWTBearerTokenValidator.get_jwks9   s   € ô "Ó#Ð#r   ÚissÚstrÚreturnc                 ó    — || j                   k(  S r   )r   )r   Úclaimsr   s      r   Úvalidate_issz$JWTBearerTokenValidator.validate_issJ   s   € ð �d—k‘kÑ!Ð!r   c                 óJ  — d| j                   dœddid| j                  dœddiddiddiddiddiddiddiddiddiddiddidœ}| j                  «       }	 t        j                  ||t
        |¬«      S # t        $ r'}t        | j                  | j                  ¬«      |‚d	}~ww xY w)
Ú T)Ú	essentialÚvalidater$   )r$   ÚvalueF)r   ÚexpÚaudÚsubÚ	client_idÚiatÚjtiÚ	auth_timeÚacrÚamrÚscopeÚgroupsÚrolesÚentitlements)ÚkeyÚ
claims_clsÚclaims_options©ÚrealmÚextra_attributesN)
r!   r   r   r   Údecoder
   r   r   r8   r9   )r   Útoken_stringr6   ÚjwksÚexcs        r   Úauthenticate_tokenz*JWTBearerTokenValidator.authenticate_tokenP   sç   € ð
 "&°4×3DÑ3DÑEØ Ð&Ø!%°×0DÑ0DÑEØ Ð&Ø% tÐ,Ø Ð&Ø Ð&Ø% uÐ-Ø Ð'Ø Ð'Ø! 5Ð)Ø" EÐ*Ø! 5Ð)Ø(¨%Ð0ñ
ˆð  �}‰}‹ˆð
	Ü—:‘:ØØÜ/Ø-ô	ð øô ò 	Ü#Ø—j‘j°4×3HÑ3Hôàðûð	ús   ÁA2 Á2	B"Á;"BÂB"c                 óæ  — 	 |j                  «        | j                  |j                  dg «      |«      r
t        «       ‚| j                  |j                  d«      |«      r
t        «       ‚| j                  |j                  d«      |«      r
t        «       ‚| j                  |j                  d«      |«      r
t        «       ‚y# t        $ r'}t        | j                  | j                  ¬«      |‚d}~ww xY w)r#   r7   Nr0   r1   r2   r3   )r%   r   r   r8   r9   Úscope_insufficientÚgetr   )r   ÚtokenÚscopesÚrequestr1   r2   r3   r=   s           r   Úvalidate_tokenz&JWTBearerTokenValidator.validate_token|   sÖ   € ð
	Ø�N‰NÔð ×"Ñ" 5§9¡9¨W°bÓ#9¸6ÔBÜ(Ó*Ð*ð ×"Ñ" 5§9¡9¨XÓ#6¸Ô?Ü#Ó%Ð%à×"Ñ" 5§9¡9¨WÓ#5°uÔ=Ü#Ó%Ð%à×"Ñ" 5§9¡9¨^Ó#<¸lÔKÜ#Ó%Ð%ð Løô? ò 	Ü#Ø—j‘j°4×3HÑ3Hôàðûð	ús   ‚C  Ã 	C0Ã	"C+Ã+C0)NNN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   Úboolr!   r>   rE   Ú__classcell__)r   s   @r   r   r      s8   ø„ ñô@*ò
$ð""¨ð "°$ó "ò*ðZ MQ÷'&r   r   N)rI   Úauthlib.joser   Úauthlib.jose.errorsr   r   Úauthlib.oauth2.rfc6750.errorsr   r   Ú authlib.oauth2.rfc6750.validatorr   r    r
   r   © r   r   ú<module>rQ      s0   ðñõ Ý +Ý )Ý @Ý ;Ý Aå (ôP&Ð2õ P&r   