Ë
    ”Âi¥!  ã                   ó^   — d dl Z d dlmZ d dlmZ d dlmZ d dlmZ d dlm	Z	  G d„ de	«      Z
y)	é    N)ÚOptional)ÚUnion©Úgenerate_token)Újwt)ÚBearerTokenGeneratorc                   ó    ‡ — e Zd ZdZ	 	 	 dˆ fd„	Zd„ Zd„ Zdeee	e   f   fd„Z
dee   fd„Zdee   fd„Zdee	e      fd	„Zdefd
„Zd„ Zˆ xZS )ÚJWTBearerTokenGeneratoraÓ  A JWT formatted access token generator.

    :param issuer: The issuer identifier. Will appear in the JWT ``iss`` claim.

    :param \\*\\*kwargs: Other parameters are inherited from
        :class:`~authlib.oauth2.rfc6750.token.BearerTokenGenerator`.

    This token generator can be registered into the authorization server::

        class MyJWTBearerTokenGenerator(JWTBearerTokenGenerator):
            def get_jwks(self): ...

            def get_extra_claims(self, client, grant_type, user, scope): ...


        authorization_server.register_token_generator(
            "default",
            MyJWTBearerTokenGenerator(
                issuer="https://authorization-server.example.org"
            ),
        )
    c                 óX   •— t         ‰| �  | j                  ||«       || _        || _        y )N)ÚsuperÚ__init__Úaccess_token_generatorÚissuerÚalg)Úselfr   r   Úrefresh_token_generatorÚexpires_generatorÚ	__class__s        €úT/var/www/timesheet/venv/lib/python3.12/site-packages/authlib/oauth2/rfc9068/token.pyr   z JWTBearerTokenGenerator.__init__"   s1   ø€ ô 	‰ÑØ×'Ñ'Ð)@ÐBSô	
ð ˆŒØˆ�ó    c                 ó   — t        «       ‚)zÊReturn the JWKs that will be used to sign the JWT access token.
        Developers MUST re-implement this method::

            def get_jwks(self):
                return load_jwks("jwks.json")
        )ÚNotImplementedError)r   s    r   Úget_jwksz JWTBearerTokenGenerator.get_jwks/   s   € ô "Ó#Ð#r   c                 ó   — i S )aY  Return extra claims to add in the JWT access token. Developers MAY
        re-implement this method to add identity claims like the ones in
        :ref:`specs/oidc` ID Token, or any other arbitrary claims::

            def get_extra_claims(self, client, grant_type, user, scope):
                return generate_user_info(user, scope)
        © ©r   ÚclientÚ
grant_typeÚuserÚscopes        r   Úget_extra_claimsz(JWTBearerTokenGenerator.get_extra_claims8   s	   € ð ˆ	r   Úreturnc                 ó"   — |j                  «       S )aj  Return the audience for the token. By default this simply returns
        the client ID. Developers MAY re-implement this method to add extra
        audiences::

            def get_audiences(self, client, user, scope):
                return [
                    client.get_client_id(),
                    resource_server.get_id(),
                ]
        )Úget_client_id)r   r   r   r    s       r   Úget_audiencesz%JWTBearerTokenGenerator.get_audiencesB   s   € ð ×#Ñ#Ó%Ð%r   c                  ó   — y)aÙ  Authentication Context Class Reference.
        Returns a user-defined case sensitive string indicating the class of
        authentication the used performed. Token audience may refuse to give access to
        some resources if some ACR criteria are not met.
        :ref:`specs/oidc` defines one special value: ``0`` means that the user
        authentication did not respect `ISO29115`_ level 1, and will be refused monetary
        operations. Developers MAY re-implement this method::

            def get_acr(self, user):
                if user.insecure_session():
                    return "0"
                return "urn:mace:incommon:iap:silver"

        .. _ISO29115: https://www.iso.org/standard/45138.html
        Nr   ©r   r   s     r   Úget_acrzJWTBearerTokenGenerator.get_acrO   s   € ð  r   c                  ó   — y)a}  User authentication time.
        Time when the End-User authentication occurred. Its value is a JSON number
        representing the number of seconds from 1970-01-01T0:0:0Z as measured in UTC
        until the date/time. Developers MAY re-implement this method::

            def get_auth_time(self, user):
                return datetime.timestamp(user.get_auth_time())
        Nr   r'   s     r   Úget_auth_timez%JWTBearerTokenGenerator.get_auth_timea   ó   € ð r   c                  ó   — y)a{  Authentication Methods References.
        Defined by :ref:`specs/oidc` as an option list of user-defined case-sensitive
        strings indication which authentication methods have been used to authenticate
        the user. Developers MAY re-implement this method::

            def get_amr(self, user):
                return ["2FA"] if user.has_2fa_enabled() else []
        Nr   r'   s     r   Úget_amrzJWTBearerTokenGenerator.get_amrl   r+   r   c                 ó   — t        d«      S )zçJWT ID.
        Create an unique identifier for the token. Developers MAY re-implement
        this method::

            def get_jti(self, client, grant_type, user scope):
                return generate_random_string(16)
        é   r   r   s        r   Úget_jtizJWTBearerTokenGenerator.get_jtiw   s   € ô ˜bÓ!Ð!r   c           
      ó®  — t        t        j                  «       «      }|| j                  ||«      z   }| j                  ||j	                  «       || j                  ||||«      |dœ}|r|j                  «       |d<   n|j	                  «       |d<   	 | j                  |||«      |d<   | j                  |«      x}r||d<   | j                  |«      x}	r|	|d<   | j                  |«      x}
r|
|d<   |j                  | j                  ||||«      «       | j                  dd	œ}t        j                  ||| j!                  «       d¬
«      }|j#                  «       S )N)ÚissÚexpÚ	client_idÚiatÚjtir    ÚsubFÚaudÚ	auth_timeÚacrÚamrzat+jwt)r   Útyp)ÚkeyÚcheck)ÚintÚtimeÚ_get_expires_inr   r$   r0   Úget_user_idr%   r*   r(   r-   Úupdater!   r   r   Úencoder   Údecode)r   r   r   r   r    ÚnowÚ
expires_inÚ
token_datar9   r:   r;   ÚheaderÚaccess_tokens                r   r   z.JWTBearerTokenGenerator.access_token_generator�   sq  € Ü”$—)‘)“+ÓˆØ˜4×/Ñ/°¸
ÓCÑCˆ
ð —;‘;ØØ×-Ñ-Ó/ØØ—<‘< ¨
°D¸%Ó@Øñ
ˆ
ñ Ø $× 0Ñ 0Ó 2ˆJ�uÒð !'× 4Ñ 4Ó 6ˆJ�uÑð ð !%× 2Ñ 2°6¸4ÀÓ GˆJ�uÑð ×*Ñ*¨4Ó0Ð0ˆ9Ð0Ø&/ˆJ�{Ñ#ð
 —,‘,˜tÓ$Ð$ˆ3Ð$Ø #ˆJ�uÑð
 —,‘,˜tÓ$Ð$ˆ3Ð$Ø #ˆJ�uÑð 	×Ñ˜$×/Ñ/°¸
ÀDÈ%ÓPÔQð Ÿ™¨(Ñ3ˆä—z‘zØØØ—‘“Øô	
ˆð ×"Ñ"Ó$Ð$r   )ÚRS256NN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r!   r   ÚstrÚlistr%   r   r(   r?   r*   r-   r0   r   Ú__classcell__)r   s   @r   r
   r
   
   s‚   ø„ ñð4 Ø $Øõò$òð&°E¸#¸tÀC¹y¸.Ñ4Ió &ð˜x¨™}ó ð$	 X¨c¡]ó 	ð	˜x¨¨S©	Ñ2ó 	ð"¸#ó "öY%r   r
   )r@   Útypingr   r   Úauthlib.common.securityr   Úauthlib.joser   Úauthlib.oauth2.rfc6750.tokenr   r
   r   r   r   ú<module>rW      s&   ðÛ Ý Ý å 2Ý Ý =ôP%Ð2õ P%r   