Ë
    ”ÂiK  ã                   óV   — d dl mZ ddlmZ ddlmZ ddlmZ ddlmZ  G d„ de«      Zy	)
é    )Údefault_json_headersé   )ÚInvalidGrantError)ÚInvalidRequestError)ÚTokenEndpoint)ÚUnsupportedTokenTypeErrorc                   ó2   — e Zd ZdZdZd„ Zd„ Zd„ Zd„ Zd„ Z	y)	ÚRevocationEndpointz†Implementation of revocation endpoint which is described in
    `RFC7009`_.

    .. _RFC7009: https://tools.ietf.org/html/rfc7009
    Ú
revocationc                 óÔ   — | j                  ||«       | j                  |j                  d   |j                  j                  d«      «      }|r|j	                  |«      s
t        «       ‚|S )a…  The client constructs the request by including the following
        parameters using the "application/x-www-form-urlencoded" format in
        the HTTP request entity-body:

        token
            REQUIRED.  The token that the client wants to get revoked.

        token_type_hint
            OPTIONAL.  A hint about the type of the token submitted for
            revocation.
        ÚtokenÚtoken_type_hint)Úcheck_paramsÚquery_tokenÚformÚgetÚcheck_clientr   ©ÚselfÚrequestÚclientr   s       úY/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth2/rfc7009/revocation.pyÚauthenticate_tokenz%RevocationEndpoint.authenticate_token   sb   € ð 	×Ñ˜' 6Ô*Ø× Ñ Ø�L‰L˜Ñ! 7§<¡<×#3Ñ#3Ð4EÓ#Fó
ˆñ ˜×+Ñ+¨FÔ3Ü#Ó%Ð%Øˆó    c                 ó    — d|j                   vr
t        «       ‚|j                   j                  d«      }|r|| j                  vr
t	        «       ‚y y )Nr   r   )r   r   r   ÚSUPPORTED_TOKEN_TYPESr   )r   r   r   Úhints       r   r   zRevocationEndpoint.check_params'   sL   € Ø˜'Ÿ,™,Ñ&Ü%Ó'Ð'à�|‰|×ÑÐ 1Ó2ˆÙ�D × :Ñ :Ñ:Ü+Ó-Ð-ð ;ˆ4r   c                 ó¾   — | j                  |«      }| j                  ||«      }|r0| j                  ||«       | j                  j	                  d||¬«       di t
        fS )aõ  Validate revocation request and create the response for revocation.
        For example, a client may request the revocation of a refresh token
        with the following request::

            POST /revoke HTTP/1.1
            Host: server.example.com
            Content-Type: application/x-www-form-urlencoded
            Authorization: Basic czZCaGRSa3F0MzpnWDFmQmF0M2JW

            token=45ghiukldjahdnhzdauz&token_type_hint=refresh_token

        :returns: (status_code, body, headers)
        Úafter_revoke_token)r   r   éÈ   )Úauthenticate_endpoint_clientr   Úrevoke_tokenÚserverÚsend_signalr   r   s       r   Úcreate_endpoint_responsez+RevocationEndpoint.create_endpoint_response/   sm   € ð ×2Ñ2°7Ó;ˆð ×'Ñ'¨°Ó8ˆñ Ø×Ñ˜e WÔ-Ø�K‰K×#Ñ#Ø$ØØð $ô ð
 �BÔ,Ð,Ð,r   c                 ó   — t        «       ‚)a7  Get the token from database/storage by the given token string.
        Developers should implement this method::

            def query_token(self, token_string, token_type_hint):
                if token_type_hint == 'access_token':
                    return Token.query_by_access_token(token_string)
                if token_type_hint == 'refresh_token':
                    return Token.query_by_refresh_token(token_string)
                return Token.query_by_access_token(token_string) or                     Token.query_by_refresh_token(token_string)
        ©ÚNotImplementedError)r   Útoken_stringr   s      r   r   zRevocationEndpoint.query_tokenN   s   € ô "Ó#Ð#r   c                 ó   — t        «       ‚)aÚ  Mark token as revoked. Since token MUST be unique, it would be
        dangerous to delete it. Consider this situation:

        1. Jane obtained a token XYZ
        2. Jane revoked (deleted) token XYZ
        3. Bob generated a new token XYZ
        4. Jane can use XYZ to access Bob's resource

        It would be secure to mark a token as revoked::

            def revoke_token(self, token, request):
                hint = request.form.get("token_type_hint")
                if hint == "access_token":
                    token.access_token_revoked = True
                else:
                    token.access_token_revoked = True
                    token.refresh_token_revoked = True
                token.save()
        r'   )r   r   r   s      r   r"   zRevocationEndpoint.revoke_token\   s   € ô( "Ó#Ð#r   N)
Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚENDPOINT_NAMEr   r   r%   r   r"   © r   r   r
   r
   	   s'   „ ñð !€Mòò(.ò-ò>$ó$r   r
   N)Úauthlib.constsr   Úrfc6749r   r   r   r   r
   r0   r   r   ú<module>r3      s"   ðÝ /å 'Ý )Ý #Ý /ôg$˜õ g$r   