Ë
    +Ñ¦h3  ã                   óÂ   — d dl Z d dlZd dlZd dlmZmZmZmZ d dlmZ d dl	m
Z
 d dlmZ d dlmZ ddlmZmZmZmZ dd	lmZ  ej,                  e«      Z G d
„ de«      Zy)é    N)Úcurrent_appÚredirectÚrequestÚurl_for)Úgenerate_token)ÚMissingCodeError)Úcached_property)ÚResponseé   )ÚBaseOAuthConsumerBlueprintÚoauth_authorizedÚoauth_before_loginÚoauth_error)ÚOAuth2Sessionc                   ó²   — e Zd ZdZ	 	 ddddddddddddddddddddddddddddœd„Zed„ «       Zej                  d„ «       Zed	„ «       Z	d
„ Z
dd„Zd„ Zd„ Zy)ÚOAuth2ConsumerBlueprintzU
    A subclass of :class:`flask.Blueprint` that sets up OAuth 2 authentication.
    NFÚS256)ÚclientÚauto_refresh_urlÚauto_refresh_kwargsÚscopeÚstateÚstatic_folderÚstatic_url_pathÚtemplate_folderÚ
url_prefixÚ	subdomainÚurl_defaultsÚ	root_pathÚ	login_urlÚauthorized_urlÚbase_urlÚauthorization_urlÚauthorization_url_paramsÚ	token_urlÚtoken_url_paramsÚredirect_urlÚredirect_toÚsession_classÚstorageÚrule_kwargsÚuse_pkceÚcode_challenge_methodc                óœ  — t        j                  | |||
||||||||||¬«       || _        |xs t        | _        || _        || _        || _        || _        || _	        |	| _
        || _        || _        || _        |xs i | _        || _        |xs i | _        || _        || _        || _        || _        | j+                  | j,                  «       y)aÀ  
        Most of the constructor arguments are forwarded either to the
        :class:`flask.Blueprint` constructor or the
        :class:`requests_oauthlib.OAuth2Session` constructor, including
        ``**kwargs`` (which is forwarded to
        :class:`~requests_oauthlib.OAuth2Session`).
        Only the arguments that are relevant to Flask-Dance are documented here.

        Args:
            base_url: The base URL of the OAuth provider.
                If specified, all URLs passed to this instance will be
                resolved relative to this URL.
            authorization_url: The URL specified by the OAuth provider for
                obtaining an
                `authorization grant <https://datatracker.ietf.org/doc/html/rfc6749#section-1.3>`__.
                This can be an fully-qualified URL, or a path that is
                resolved relative to the ``base_url``.
            authorization_url_params (dict): A dict of extra
                key-value pairs to include in the query string of the
                ``authorization_url``, beyond those necessary for a standard
                OAuth 2 authorization grant request.
            token_url: The URL specified by the OAuth provider for
                obtaining an
                `access token <https://datatracker.ietf.org/doc/html/rfc6749#section-1.4>`__.
                This can be an fully-qualified URL, or a path that is
                resolved relative to the ``base_url``.
            token_url_params (dict): A dict of extra
                key-value pairs to include in the query string of the
                ``token_url``, beyond those necessary for a standard
                OAuth 2 access token request.
            login_url: The URL route for the ``login`` view that kicks off
                the OAuth dance. This string will be
                :ref:`formatted <python:formatstrings>`
                with the instance so that attributes can be interpolated.
                Defaults to ``/{bp.name}``, so that the URL is based on the name
                of the blueprint.
            authorized_url: The URL route for the ``authorized`` view that
                completes the OAuth dance. This string will be
                :ref:`formatted <python:formatstrings>`
                with the instance so that attributes can be interpolated.
                Defaults to ``/{bp.name}/authorized``, so that the URL is
                based on the name of the blueprint.
            redirect_url: When the OAuth dance is complete,
                redirect the user to this URL.
            redirect_to: When the OAuth dance is complete,
                redirect the user to the URL obtained by calling
                :func:`~flask.url_for` with this argument. If you do not specify
                either ``redirect_url`` or ``redirect_to``, the user will be
                redirected to the root path (``/``).
            session_class: The class to use for creating a Requests session
                between the consumer (your website) and the provider (e.g.
                Google). Defaults to
                :class:`~flask_dance.consumer.requests.OAuth2Session`.
            storage: A token storage class, or an instance of a token storage
                class, to use for this blueprint. Defaults to
                :class:`~flask_dance.consumer.storage.session.SessionStorage`.
            rule_kwargs (dict, optional): Additional arguments that should be passed when adding
                the login and authorized routes. Defaults to ``None``.
            use_pkce: If true then the authorization flow will follow the PKCE (Proof Key for Code Exchange).
                For more details please refer to `RFC7636 <https://www.rfc-editor.org/rfc/rfc7636#section-4.1>`__
            code_challenge_method: Code challenge method to be used in authorization code flow with PKCE
                instead of client secret. It will be used only if ``use_pkce`` is set to True.
                Defaults to ``S256``.
        )r   r   r   r   r   r   r   r    r!   r*   r+   N)r   Ú__init__r"   r   r)   Ú
_client_idr   r   r   r   r   ÚkwargsÚclient_secretr#   r$   r%   r&   r'   r(   r-   r,   Úteardown_app_requestÚteardown_session) ÚselfÚnameÚimport_nameÚ	client_idr2   r   r   r   r   r   r   r   r   r   r   r   r   r    r!   r"   r#   r$   r%   r&   r'   r(   r)   r*   r+   r,   r-   r1   s                                    úS/var/www/timesheet/venv/lib/python3.12/site-packages/flask_dance/consumer/oauth2.pyr/   z OAuth2ConsumerBlueprint.__init__   sî   € ôF 	#×+Ñ+ØØØØ'Ø+Ø+Ø!ØØ%ØØØ)ØØ#õ	
ð" !ˆŒØ*Ò;¬mˆÔð $ˆŒØˆŒØ 0ˆÔØ#6ˆÔ ØˆŒ
ØˆŒ
ØˆŒØ*ˆÔð "3ˆÔØ(@Ò(FÀBˆÔ%Ø"ˆŒØ 0Ò 6°BˆÔØ(ˆÔØ&ˆÔØ%:ˆÔ"Ø ˆŒà×!Ñ! $×"7Ñ"7Õ8ó    c                 ó.   — | j                   j                  S ©N)Úsessionr8   )r5   s    r9   r8   z!OAuth2ConsumerBlueprint.client_id¨   s   € à�|‰|×%Ñ%Ð%r:   c                 ó\   — || j                   _        || j                   j                  _        y r<   )r=   r8   Ú_client)r5   Úvalues     r9   r8   z!OAuth2ConsumerBlueprint.client_id¬   s    € à!&ˆ�‰Ôà).ˆ�‰×ÑÕ&r:   c                 ó  ‡ —  ‰ j                   d‰ j                  ‰ j                  ‰ j                  ‰ j                  ‰ j
                  ‰ j                  ‰ ‰ j                  dœ‰ j                  ¤Ž}ˆ fd„}||_	        ‰ j                  |«      S )zÏ
        This is a session between the consumer (your website) and the provider
        (e.g. Google). It is *not* a session between a user of your website
        and your website.
        :return:
        )r8   r   r   r   r   r   Ú	blueprintr"   c                 ó   •— | ‰_         y r<   ©Útoken)rE   r5   s    €r9   Útoken_updaterz6OAuth2ConsumerBlueprint.session.<locals>.token_updaterÆ   s
   ø€ ØˆD�Jr:   © )r)   r0   r   r   r   r   r   r"   r1   rF   Úsession_created)r5   ÚretrF   s   `  r9   r=   zOAuth2ConsumerBlueprint.session²   s‚   ø€ ð !ˆd× Ñ ð 

Ø—o‘oØ—;‘;Ø!×2Ñ2Ø $× 8Ñ 8Ø—*‘*Ø—*‘*ØØ—]‘]ñ

ð �k‰kñ

ˆô	ð *ˆÔØ×#Ñ# CÓ(Ð(r:   c                 ó   — |S r<   rG   )r5   r=   s     r9   rH   z'OAuth2ConsumerBlueprint.session_createdÌ   s   € Øˆr:   c                 ó(   — 	 | ` y # t        $ r Y y w xY wr<   )r=   ÚKeyError)r5   Ú	exceptions     r9   r4   z(OAuth2ConsumerBlueprint.teardown_sessionÏ   s   € ð	Ø‘øÜò 	Ùð	ús   ‚ …	�c                 ó,  — t         j                  d| j                  «       t        dd¬«      | j                  _        | j                  r�t        d¬«      }| j                  j                  j                  || j                  ¬«      }| j                  j                  | j                  |dœ«       | j                  › d	�}|t        j                  |<   t         j                  d
|«        | j                  j                  | j                  fd| j                   i| j                  ¤Ž\  }}| j                  › d�}|t        j                  |<   t         j                  d|«       t         j                  d|«       t#        j$                  | |¬«       t'        |«      S )Núclient_id = %sú.authorizedT©Ú	_externalé0   )Úlength)Úcode_verifierr-   )r-   Úcode_challengeÚ_oauth_code_verifierúcode_verifier = %sr   Ú_oauth_stateú
state = %szredirect URL = %s)Úurl)ÚlogÚdebugr8   r   r=   Úredirect_urir,   r   r?   Úcreate_code_challenger-   r$   Úupdater6   Úflaskr#   r   r   Úsendr   )r5   rU   rV   Úcode_verifier_keyr[   r   Ú	state_keys          r9   ÚloginzOAuth2ConsumerBlueprint.loginÕ   sR  € Ü�	‰	Ð" D§N¡NÔ3Ü$+¨MÀTÔ$Jˆ�‰Ô!Ø�=Š=Ü*°"Ô5ˆMØ!Ÿ\™\×1Ñ1×GÑGØ+Ø&*×&@Ñ&@ð Hó ˆNð ×)Ñ)×0Ñ0à-1×-GÑ-GØ&4ñôð $(§9¡9 +Ð-AÐ BÐØ/<ŒE�M‰MÐ+Ñ,Ü�I‰IÐ*¨MÔ:à3�T—\‘\×3Ñ3Ø×"Ñ"ñ
Ø*.¯*©*ð
Ø8<×8UÑ8Uñ
‰
ˆˆUð —y‘y�k Ð.ˆ	Ø#(Œ�‰�iÑ Ü�	‰	�, Ô&Ü�	‰	Ð% sÔ+Ü×Ñ ¨#Õ.Ü˜‹}Ðr:   c                 ó:  — | j                   r| j                   }n$| j                  rt        | j                  «      }nd}t        j	                  d|«       t
        j                  j                  d«      }|rªt
        j                  j                  d«      }t
        j                  j                  d«      }t        j                  d|||«       t        j                  | |||¬«      }|r.|D ])  \  }}t        |t        t        j                  f«      sŒ'|c S  t        |«      S | j                   › d�}|t"        j$                  vr)t        j'                  d	«       t        t        d
«      «      S t"        j$                  |   }	t        j	                  d|	«       |	| j$                  _        t"        j$                  |= | j*                  r“| j                   › d�}
|
t"        j$                  vr)t        j'                  d«       t        t        d
«      «      S t"        j$                  |
   }t        j	                  d|«       t"        j$                  |
= || j,                  d<   t        dd¬«      | j$                  _        t        j	                  d| j0                  «       t        j	                  d| j2                  «       	  | j$                  j4                  | j6                  ft
        j8                  | j2                  dœ| j,                  ¤Ž}tC        j                  | |¬«      xs g }d}|D ]1  \  }}t        |t        t        j                  f«      r|c S |dk(  sŒ0d}Œ3 |r	 || _"        t        |«      S t        |«      S # t:        $ rL}|j                  d   dj=                  t?        j@                  t
        j                  «      «      f|_        ‚ d}~ww xY w# tF        $ rJ}t        j                  dtI        |«      «       t        j                  | |¬«       Y d}~t        |«      S d}~ww xY w)zå
        This is the route/function that the user will be redirected to by
        the provider (e.g. Google) after the user has logged into the
        provider's website and authorized your app to access their account.
        ú/znext_url = %sÚerrorÚerror_descriptionÚ	error_uriz7OAuth 2 authorization error: %s description: %s uri: %s)rh   ri   rj   rY   z*state not found, redirecting user to loginz.loginrZ   rW   z2code_verifier not found, redirecting user to loginrX   rU   rP   TrQ   rO   zclient_secret = %s)Úauthorization_responser2   r   zOThe redirect request did not contain the expected parameters. Instead I got: {}NrD   FzOAuth 2 authorization error: %s)rh   )%r'   r(   r   r\   r]   r   ÚargsÚgetÚwarningr   rb   Ú
isinstancer
   r   Úresponse_classr   r6   ra   r=   ÚinfoÚ_stater,   r&   r^   r8   r2   Úfetch_tokenr%   r[   r   ÚformatÚjsonÚdumpsr   rE   Ú
ValueErrorÚstr)r5   Únext_urlrh   Ú
error_descrj   ÚresultsÚ_rI   rd   r   rc   rU   rE   ÚeÚ	set_tokenÚfuncs                   r9   Ú
authorizedz"OAuth2ConsumerBlueprint.authorizedò   sn  € ð ×ÒØ×(Ñ(‰HØ×ÒÜ˜t×/Ñ/Ó0‰HàˆHÜ�	‰	�/ 8Ô,ô —‘× Ñ  Ó)ˆÙÜ Ÿ™×)Ñ)Ð*=Ó>ˆJÜŸ™×(Ñ(¨Ó5ˆIÜ�K‰KØIØØØô	ô "×&Ñ&Ø˜E°ZÈ9ôˆGñ Ø%ò #‘F�A�sÜ! #¬´+×2LÑ2LÐ'MÕNØ"š
ð#ô ˜HÓ%Ð%à—y‘y�k Ð.ˆ	ØœEŸM™MÑ)ä�H‰HÐAÔBÜœG HÓ-Ó.Ð.ä—‘˜iÑ(ˆÜ�	‰	�, Ô&Ø#ˆ�‰ÔÜ�M‰M˜)Ð$à�=Š=Ø#'§9¡9 +Ð-AÐ BÐØ ¬¯©Ñ5ä—‘ÐMÔNÜ¤¨Ó 1Ó2Ð2ä!ŸM™MÐ*;Ñ<ˆMÜ�I‰IÐ*¨MÔ:Ü—‘Ð/Ð0Ø5BˆD×!Ñ! /Ñ2ä$+¨MÀTÔ$Jˆ�‰Ô!ä�	‰	Ð" D§N¡NÔ3Ü�	‰	Ð&¨×(:Ñ(:Ô;ð	Ø,�D—L‘L×,Ñ,Ø—‘ðä'.§{¡{Ø"×0Ñ0ñð ×'Ñ'ñ	ˆEô #×'Ñ'¨°EÔ:Ò@¸bˆØˆ	Ø ò 	"‰IˆD�#Ü˜#¤¬+×*DÑ*DÐEÔFØ’
Ø�e‹|Ø!‘	ð		"ñ ð4Ø"�”
ô ˜Ó!Ð!Œx˜Ó!Ð!øô/  ò 	à—‘�q‘	Øa×hÑhÜ—J‘JœwŸ|™|Ó,óðˆAŒFð ûð	ûô( ò 4Ü—‘Ð=¼sÀ5»zÔJÜ× Ñ  ¨U×3Ñ3Ü˜Ó!Ð!ûð4ús2   Ê0AM/ ÍO Í/	OÍ8AN?Î?OÏ	PÏ6PÐP)NNr<   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r/   Úpropertyr8   Úsetterr	   r=   rH   r4   re   r€   rG   r:   r9   r   r      sÄ   „ ñð ØðK9ð ØØ ØØØØØØØØØØØØØØ!%ØØØØØØØØØ$ôAK9ðZ ñ&ó ð&ð ×Ññ/ó ð/ð
 ñ)ó ð)ò2óòó:["r:   r   )ru   Úloggingra   r   r   r   r   Úoauthlib.commonr   Úoauthlib.oauth2r   Úwerkzeug.utilsr	   Úwerkzeug.wrappersr
   Úbaser   r   r   r   Úrequestsr   Ú	getLoggerr�   r\   r   rG   r:   r9   ú<module>r�      sP   ðÛ Û ã ß 9Ó 9Ý *Ý ,Ý *Ý &÷ó õ $à€g×Ñ˜Ó!€ôw"Ð8õ w"r:   