Ë
    ”Âi:  ã                   ó¸   — d dl Z d dlmZ d dlmZ ddlmZ ddlmZ ddlmZ ddlmZ dd	lm	Z	 dd
lm
Z
 ddlmZ  e j                  e«      ZdZ G d„ dee	«      Zy)é    N)Ú	JoseError)Újwté   )Ú	BaseGrant)ÚInvalidClientError)ÚInvalidGrantError)ÚInvalidRequestError)ÚTokenEndpointMixin)ÚUnauthorizedClientErroré   ©Úsign_jwt_bearer_assertionz+urn:ietf:params:oauth:grant-type:jwt-bearerc                   óv   — e Zd ZeZddiddiddidœZdZe	 	 	 	 dd„«       Zd„ Z	d„ Z
d	„ Zd
„ Zd„ Zd„ Zd„ Zd„ Zy)ÚJWTBearerGrantÚ	essentialT)ÚissÚaudÚexpé<   Nc           	      ó&   — t        | ||||||fi |¤ŽS )Nr   )ÚkeyÚissuerÚaudienceÚsubjectÚ	issued_atÚ
expires_atÚclaimsÚkwargss           úY/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth2/rfc7523/jwt_bearer.pyÚsignzJWTBearerGrant.sign!   s(   € ô )Ø�˜ 7¨I°zÀ6ñ
ØMSñ
ð 	
ó    c                 ó  — 	 t        j                  || j                  | j                  ¬«      }|j	                  | j
                  ¬«       |S # t        $ r2}t        j                  d|«       t        |j                  ¬«      |‚d}~ww xY w)a#  Extract JWT payload claims from request "assertion", per
        `Section 3.1`_.

        :param assertion: assertion string value in the request
        :return: JWTClaims
        :raise: InvalidGrantError

        .. _`Section 3.1`: https://tools.ietf.org/html/rfc7523#section-3.1
        )Úclaims_options)ÚleewayzAssertion Error: %r©ÚdescriptionN)r   ÚdecodeÚresolve_public_keyÚCLAIMS_OPTIONSÚvalidateÚLEEWAYr   ÚlogÚdebugr   r&   )ÚselfÚ	assertionr   Úes       r   Úprocess_assertion_claimsz'JWTBearerGrant.process_assertion_claims0   sx   € ð	FÜ—Z‘ZØ˜4×2Ñ2À4×CVÑCVôˆFð �O‰O 4§;¡;ˆOÔ/ð ˆøô ò 	FÜ�I‰IÐ+¨QÔ/Ü#°·±Ô>ÀAÐEûð	Fús   ‚AA Á	BÁ-BÂBc                 óP   — | j                  |d   «      }| j                  |||«      S )Nr   )Úresolve_issuer_clientÚresolve_client_key)r.   ÚheadersÚpayloadÚclients       r   r(   z!JWTBearerGrant.resolve_public_keyD   s+   € Ø×+Ñ+¨G°E©NÓ;ˆØ×&Ñ& v¨w¸Ó@Ð@r!   c                 óz  — | j                   j                  j                  d«      }|st        d«      ‚| j	                  |«      }| j                  |d   «      }t        j                  d|«       |j                  | j                  «      st        d| j                  › d�«      ‚|| j                   _        | j                  «        |j                  d«      }|rf| j                  |«      }|st        d¬	«      ‚t        j                  d
||«       | j                  ||«      st!        d¬	«      ‚|| j                   _        yy)añ  The client makes a request to the token endpoint by sending the
        following parameters using the "application/x-www-form-urlencoded"
        format per `Section 2.1`_:

        grant_type
             REQUIRED.  Value MUST be set to
             "urn:ietf:params:oauth:grant-type:jwt-bearer".

        assertion
             REQUIRED.  Value MUST contain a single JWT.

        scope
            OPTIONAL.

        The following example demonstrates an access token request with a JWT
        as an authorization grant:

        .. code-block:: http

            POST /token.oauth2 HTTP/1.1
            Host: as.example.com
            Content-Type: application/x-www-form-urlencoded

            grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer
            &assertion=eyJhbGciOiJFUzI1NiIsImtpZCI6IjE2In0.
            eyJpc3Mi[...omitted for brevity...].
            J9l-ZhwP[...omitted for brevity...]

        .. _`Section 2.1`: https://tools.ietf.org/html/rfc7523#section-2.1
        r/   zMissing 'assertion' in requestr   zValidate token request of %sz0The client is not authorized to use 'grant_type=ú'Úsubz Invalid 'sub' value in assertionr%   z'Check client(%s) permission to User(%s)z,Client has no permission to access user dataN)ÚrequestÚformÚgetr	   r1   r3   r,   r-   Úcheck_grant_typeÚ
GRANT_TYPEr   r7   Úvalidate_requested_scopeÚauthenticate_userr   Úhas_granted_permissionr   Úuser)r.   r/   r   r7   r   rC   s         r   Úvalidate_token_requestz%JWTBearerGrant.validate_token_requestH   s  € ð> —L‘L×%Ñ%×)Ñ)¨+Ó6ˆ	ÙÜ%Ð&FÓGÐGà×.Ñ.¨yÓ9ˆØ×+Ñ+¨F°5©MÓ:ˆÜ�	‰	Ð0°&Ô9à×&Ñ& t§¡Ô7Ü)ØBÀ4Ç?Á?ÐBSÐSTÐUóð ð %ˆ�‰ÔØ×%Ñ%Ô'à—*‘*˜UÓ#ˆÙØ×)Ñ)¨'Ó2ˆDÙÜ'Ð4VÔWÐWä�I‰IÐ?ÀÈÔNØ×.Ñ.¨v°tÔ<Ü(Ø Nôð ð !%ˆD�L‰LÕð r!   c                 ó$  — | j                  | j                  j                  j                  | j                  j                  d¬«      }t
        j                  d|| j                  j                  «       | j                  |«       d|| j                  fS )zZIf valid and authorized, the authorization server issues an access
        token.
        F)ÚscoperC   Úinclude_refresh_tokenzIssue token %r to %réÈ   )
Úgenerate_tokenr;   r6   rF   rC   r,   r-   r7   Ú
save_tokenÚTOKEN_RESPONSE_HEADER)r.   Útokens     r   Úcreate_token_responsez$JWTBearerGrant.create_token_response„   sx   € ð ×#Ñ#Ø—,‘,×&Ñ&×,Ñ,Ø—‘×"Ñ"Ø"'ð $ó 
ˆô
 	�	‰	Ð(¨%°·±×1DÑ1DÔEØ�‰˜ÔØ�E˜4×5Ñ5Ð5Ð5r!   c                 ó   — t        «       ‚)a1  Fetch client via "iss" in assertion claims. Developers MUST
        implement this method in subclass, e.g.::

            def resolve_issuer_client(self, issuer):
                return Client.query_by_iss(issuer)

        :param issuer: "iss" value in assertion
        :return: Client instance
        ©ÚNotImplementedError)r.   r   s     r   r3   z$JWTBearerGrant.resolve_issuer_client‘   ó   € ô "Ó#Ð#r!   c                 ó   — t        «       ‚)au  Resolve client key to decode assertion data. Developers MUST
        implement this method in subclass. For instance, there is a
        "jwks" column on client table, e.g.::

            def resolve_client_key(self, client, headers, payload):
                # from authlib.jose import JsonWebKey

                key_set = JsonWebKey.import_key_set(client.jwks)
                return key_set.find_by_kid(headers["kid"])

        :param client: instance of OAuth client model
        :param headers: headers part of the JWT
        :param payload: payload part of the JWT
        :return: ``authlib.jose.Key`` instance
        rO   )r.   r7   r5   r6   s       r   r4   z!JWTBearerGrant.resolve_client_key�   s   € ô  "Ó#Ð#r!   c                 ó   — t        «       ‚)a%  Authenticate user with the given assertion claims. Developers MUST
        implement it in subclass, e.g.::

            def authenticate_user(self, subject):
                return User.get_by_sub(subject)

        :param subject: "sub" value in claims
        :return: User instance
        rO   )r.   r   s     r   rA   z JWTBearerGrant.authenticate_user¯   rQ   r!   c                 ó   — t        «       ‚)a¶  Check if the client has permission to access the given user's resource.
        Developers MUST implement it in subclass, e.g.::

            def has_granted_permission(self, client, user):
                permission = ClientUserGrant.query(client=client, user=user)
                return permission.granted

        :param client: instance of OAuth client model
        :param user: instance of User model
        :return: bool
        rO   )r.   r7   rC   s      r   rB   z%JWTBearerGrant.has_granted_permission»   s   € ô "Ó#Ð#r!   )NNNN)Ú__name__Ú
__module__Ú__qualname__ÚJWT_BEARER_GRANT_TYPEr?   r)   r+   Ústaticmethodr    r1   r(   rD   rM   r3   r4   rA   rB   © r!   r   r   r      sy   „ Ø&€Jð
 ˜TÐ"Ø˜TÐ"Ø˜TÐ"ñ€Nð €Fàð
 ØØØò
ó ð
òò(Aò:%òx6ò
$ò$ò$
$ó$r!   r   )ÚloggingÚauthlib.joser   r   Úrfc6749r   r   r   r	   r
   r   r/   r   Ú	getLoggerrU   r,   rX   r   rZ   r!   r   ú<module>r_      sL   ðÛ å "Ý å Ý (Ý 'Ý )Ý (Ý -Ý 0à€g×Ñ˜Ó!€ØEÐ ôu$�YÐ 2õ u$r!   