ó
    ych+  ã                   óè   • S r SSKrSSKrSSKrSSKJr  SSKJr  SSKJ	r	  SSK
JrJr  SSKJr   " S	 S
\5      r       SS jrS rSS jrSS jrSS jrS rS r " S S5      r " S S\5      rg)zÿ
oauthlib.oauth2.rfc6749.tokens
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This module contains methods for adding two types of access tokens to requests.

- Bearer https://tools.ietf.org/html/rfc6750
- MAC https://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01
é    N)Ú
b2a_base64)Úurlparse)Úcommon)Úadd_params_to_qsÚadd_params_to_urié   )Úutilsc                   óœ   ^ • \ rS rSrSU 4S jjr\S 5       r\S 5       r\S 5       r\S 5       r	\S 5       r
\S 5       r\S	 5       rS
rU =r$ )ÚOAuth2Tokené   c                 ó\  >• [         TU ]  U5        S U l        UR                  S5      (       a'  [	        [
        R                  " US   5      5      U l        UbD  [	        [
        R                  " U5      5      U l        U R                  c  U R                  U l        g g U R                  U l        g )NÚscope)ÚsuperÚ__init__Ú
_new_scopeÚgetÚsetr	   Úscope_to_listÚ
_old_scope)ÚselfÚparamsÚ	old_scopeÚ	__class__s      €Úg/var/www/djangovue.mamus.xyz/django/venv/lib/python3.13/site-packages/oauthlib/oauth2/rfc6749/tokens.pyr   ÚOAuth2Token.__init__   s‡   ø€ Ü‰Ñ˜Ô ØˆŒØ�:‰:�g×ÑÜ!¤%×"5Ò"5°f¸W±oÓ"FÓGˆDŒOØÑ Ü!¤%×"5Ò"5°iÓ"@ÓAˆDŒOØ�‰Ñ&ð #'§/¡/�•ð 'ð
 #Ÿo™oˆD�Oó    c                 ó4   • U R                   U R                  :g  $ ©N©r   r   ©r   s    r   Úscope_changedÚOAuth2Token.scope_changed&   s   € à�‰ $§/¡/Ñ1Ð1r   c                 óB   • [         R                  " U R                  5      $ r   )r	   Úlist_to_scoper   r    s    r   r   ÚOAuth2Token.old_scope*   ó   € ä×"Ò" 4§?¡?Ó3Ð3r   c                 ó,   • [        U R                  5      $ r   )Úlistr   r    s    r   Ú
old_scopesÚOAuth2Token.old_scopes.   ó   € ä�D—O‘OÓ$Ð$r   c                 óB   • [         R                  " U R                  5      $ r   )r	   r$   r   r    s    r   r   ÚOAuth2Token.scope2   r&   r   c                 ó,   • [        U R                  5      $ r   )r(   r   r    s    r   ÚscopesÚOAuth2Token.scopes6   r+   r   c                 óF   • [        U R                  U R                  -
  5      $ r   )r(   r   r   r    s    r   Úmissing_scopesÚOAuth2Token.missing_scopes:   ó   € ä�D—O‘O d§o¡oÑ5Ó6Ð6r   c                 óF   • [        U R                  U R                  -
  5      $ r   )r(   r   r   r    s    r   Úadditional_scopesÚOAuth2Token.additional_scopes>   r4   r   r   r   )Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__r   Úpropertyr!   r   r)   r   r/   r2   r6   Ú__static_attributes__Ú__classcell__)r   s   @r   r   r      s”   ø† ÷.ð ñ2ó ð2ð ñ4ó ð4ð ñ%ó ð%ð ñ4ó ð4ð ñ%ó ð%ð ñ7ó ð7ð ñ7ó ö7r   r   c                 ó¸  • UR                  5       n[        R                  " U5      u  p¼UR                  5       S:X  a  [        R
                  nO0UR                  5       S:X  a  [        R                  nO[        S5      eU
S:X  aC  U=(       d9    SR                  [        R                  " U	5      [        R                  " 5       5      nO*[        R                  " 5       n[        R                  " 5       n[        U5      u  nnnnnnU(       a  US-   U-   OUnUbI  U
S:X  aC  UR                  S5      n[        U" U5      R!                  5       5      SS	 R#                  S5      nOS
n/ nU
S:X  a  UR%                  U5        O"UR%                  W5        UR%                  U5        UR%                  UR                  5       5        UR%                  U5        UR%                  U5        UR%                  U5        U
S:X  a  UR%                  U5        UR%                  U=(       d    S
5        SR'                  U5      S-   n[)        U[*        5      (       a  UR                  S5      n[,        R.                  " UUR                  S5      U5      n[        UR!                  5       5      SS	 R#                  S5      n/ nUR%                  SU -  5        U
S:w  a  UR%                  SW-  5        UR%                  SU-  5        U(       a  UR%                  SU-  5        U(       a  UR%                  SU-  5        UR%                  SU-  5        U=(       d    0 nSR'                  U5      US'   U$ )aû  Add an `MAC Access Authentication`_ signature to headers.

Unlike OAuth 1, this HMAC signature does not require inclusion of the
request payload/body, neither does it use a combination of client_secret
and token_secret but rather a mac_key provided together with the access
token.

Currently two algorithms are supported, "hmac-sha-1" and "hmac-sha-256",
`extension algorithms`_ are not supported.

Example MAC Authorization header, linebreaks added for clarity

Authorization: MAC id="h480djs93hd8",
                   nonce="1336363200:dj83hs9s",
                   mac="bhCQXTVyfj5cmA9uKkPFx1zeOXM="

.. _`MAC Access Authentication`: https://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01
.. _`extension algorithms`: https://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01#section-7.1

:param token:
:param uri: Request URI.
:param key: MAC given provided by token endpoint.
:param http_method: HTTP Request method.
:param nonce:
:param headers: Request headers as a dictionary.
:param body:
:param ext:
:param hash_algorithm: HMAC algorithm provided by token endpoint.
:param issue_time: Time when the MAC credentials were issued (datetime).
:param draft: MAC authentication specification version.
:return: headers dictionary with the authorization field added.
ú
hmac-sha-1zhmac-sha-256zunknown hash algorithmr   z{}:{}Ú?Nzutf-8éÿÿÿÿÚ Ú
zMAC id="%s"zts="%s"z
nonce="%s"zbodyhash="%s"zext="%s"zmac="%s"z, ÚAuthorization)Úupperr	   Úhost_from_uriÚlowerÚhashlibÚsha1Úsha256Ú
ValueErrorÚformatÚgenerate_ager   Úgenerate_nonceÚgenerate_timestampr   Úencoder   ÚdigestÚdecodeÚappendÚjoinÚ
isinstanceÚstrÚhmacÚnew)ÚtokenÚuriÚkeyÚhttp_methodÚnonceÚheadersÚbodyÚextÚhash_algorithmÚ
issue_timeÚdraftÚhostÚportÚhÚtsÚschÚnetÚpathÚparÚqueryÚfraÚrequest_uriÚbodyhashÚbaseÚbase_stringÚsignÚheaders                              r   Úprepare_mac_headerru   C   s½  € ðP ×#Ñ#Ó%€KÜ×$Ò$ SÓ)�J€Dà×ÑÓ Ó-Ü�L‰L‰Ø	×	Ñ	Ó	 >Ó	1Ü�N‰N‰äÐ1Ó2Ð2à�ƒzØ÷ C˜Ÿ™¬×(:Ò(:¸:Ó(FÜ*0×*?Ò*?Ó*AóC‰ô ×&Ò&Ó(ˆÜ×%Ò%Ó'ˆä&.¨s£mÑ#€Cˆˆd�C˜ æ(-�$˜‘*˜uÒ$°4€Kð Ñ˜E Q›JØ�{‰{˜7Ó#ˆÜ™a ›gŸn™nÓ.Ó/°°Ð4×;Ñ;¸GÓD‰àˆð €DØ�ƒzØ�‰�EÕà�‰�BŒØ�‰�EÔØ‡K�K�×!Ñ!Ó#Ô$Ø‡K�K�ÔØ‡K�K�ÔØ‡K�K�ÔØ�ƒzØ�‰�HÔØ‡K�K�—	�rÔØ—)‘)˜D“/ DÑ(€Kô �#”s×ÑØ�j‰j˜Ó!ˆÜ�8Š8�C˜×+Ñ+¨GÓ4°aÓ8€DÜ�d—k‘k“mÓ$ S bÐ)×0Ñ0°Ó9€Dà€FØ
‡M�M�- %Ñ'Ô(Ø�ƒzØ�‰�i "‘nÔ%Ø
‡M�M�, Ñ&Ô'ÞØ�‰�o¨Ñ0Ô1Þ
Ø�‰�j 3Ñ&Ô'Ø
‡M�M�*˜tÑ#Ô$à�m˜€GØ#Ÿy™y¨Ó0€GˆOÑØ€Nr   c                 ó    • [        USU 4/5      $ )a  Add a `Bearer Token`_ to the request URI.
Not recommended, use only if client can't use authorization header or body.

http://www.example.com/path?access_token=h480djs93hd8

.. _`Bearer Token`: https://tools.ietf.org/html/rfc6750

:param token:
:param uri:
Úaccess_token)r   )rZ   r[   s     r   Úprepare_bearer_urirx   ­   s   € ô ˜S ^°UÐ$;Ð"=Ó>Ð>r   c                 ó,   • U=(       d    0 nSU -  US'   U$ )zÓAdd a `Bearer Token`_ to the request URI.
Recommended method of passing bearer tokens.

Authorization: Bearer h480djs93hd8

.. _`Bearer Token`: https://tools.ietf.org/html/rfc6750

:param token:
:param headers:
z	Bearer %srE   © )rZ   r_   s     r   Úprepare_bearer_headersr{   »   s!   € ð �m˜€GØ*¨UÑ2€GˆOÑØ€Nr   c                 ó    • [        USU 4/5      $ )z›Add a `Bearer Token`_ to the request body.

access_token=h480djs93hd8

.. _`Bearer Token`: https://tools.ietf.org/html/rfc6750

:param token:
:param body:
rw   )r   )rZ   r`   s     r   Úprepare_bearer_bodyr}   Ë   s   € ô ˜D ^°UÐ$;Ð"=Ó>Ð>r   c                 ó,   • [         R                  " 5       $ )z`
:param request: OAuthlib request.
:type request: oauthlib.common.Request
:param refresh_token:
)r   Úgenerate_token)ÚrequestÚrefresh_tokens     r   Úrandom_token_generatorr‚   Ø   s   € ô × Ò Ó"Ð"r   c                 ó   ^ ^• UU 4S jnU$ )z
:param private_pem:
c                 ó@   >• TU l         [        R                  " TU 5      $ r   )Úclaimsr   Úgenerate_signed_token)r€   ÚkwargsÚprivate_pems    €€r   Úsigned_token_generatorÚ6signed_token_generator.<locals>.signed_token_generatorå   s   ø€ ØˆŒÜ×+Ò+¨K¸ÓAÐAr   rz   )rˆ   r‡   r‰   s   `` r   r‰   r‰   á   s   ù€ öBð "Ð!r   c                 óî   • SnSU R                   ;   aV  U R                   R                  S5      R                  5       n[        U5      S:X  a  US   R	                  5       S:X  a  US   nU$ U R
                  nU$ )zÓ
Helper function to extract a token from the request header.

:param request: OAuthlib request.
:type request: oauthlib.common.Request
:return: Return the token or None if the Authorization header is malformed.
NrE   é   r   Úbearerr   )r_   r   ÚsplitÚlenrH   rw   )r€   rZ   Úsplit_headers      r   Úget_token_from_headerr‘   ì   su   € ð €Eà˜'Ÿ/™/Ó)Ø—‘×*Ñ*¨?Ó;×AÑAÓCˆÜˆ|Ó Ó! l°1¡o×&;Ñ&;Ó&=ÀÓ&IØ  ‘OˆEð €Lð ×$Ñ$ˆà€Lr   c                   ó.   • \ rS rSrSrSS jrS rS rSrg)Ú	TokenBaseé   rz   c                 ó   • [        S5      e)Nú&Subclasses must implement this method.©ÚNotImplementedError)r   r€   r�   s      r   Ú__call__ÚTokenBase.__call__  s   € Ü!Ð"JÓKÐKr   c                 ó   • [        S5      e©úJ
:param request: OAuthlib request.
:type request: oauthlib.common.Request
r–   r—   ©r   r€   s     r   Úvalidate_requestÚTokenBase.validate_request  ó   € ô
 "Ð"JÓKÐKr   c                 ó   • [        S5      erœ   r—   rž   s     r   Úestimate_typeÚTokenBase.estimate_type  r¡   r   N©F)	r8   r9   r:   r;   Ú	__slots__r™   rŸ   r£   r=   rz   r   r   r“   r“      s   † Ø€IôLòLõLr   r“   c                   ó<   • \ rS rSrSr  S	S jrS
S jrS rS rSr	g)ÚBearerTokeni  )Úrequest_validatorÚtoken_generatorÚrefresh_token_generatorÚ
expires_inNc                 óŒ   • Xl         U=(       d    [        U l        U=(       d    U R                  U l        U=(       d    SU l        g )Ni  )r©   r‚   rª   r«   r¬   )r   r©   rª   r¬   r«   s        r   r   ÚBearerToken.__init__  s:   € à!2ÔØ.×HÔ2HˆÔà#×; t×';Ñ';ð 	Ô$ð %×,¨ˆ�r   c                 óT  • SU;   a  [         R                  " S[        5        [        U R                  5      (       a  U R	                  U5      OU R                  nXAl        U R                  U5      USS.nUR                  b  SR                  UR                  5      US'   U(       aU  UR                  (       a0  U R                  R                  U5      (       d  UR                  US'   OU R                  U5      US'   UR                  UR                  =(       d    0 5        [        U5      $ )z™
Create a BearerToken, by default without refresh token.

:param request: OAuthlib request.
:type request: oauthlib.common.Request
:param refresh_token:
Ú
save_tokenzx`save_token` has been deprecated, it was not called internally.If you do, call `request_validator.save_token()` instead.ÚBearer)rw   r¬   Ú
token_typeÚ r   r�   )ÚwarningsÚwarnÚDeprecationWarningÚcallabler¬   rª   r/   rU   r�   r©   Úrotate_refresh_tokenr«   ÚupdateÚextra_credentialsr   )r   r€   r�   r‡   r¬   rZ   s         r   Úcreate_tokenÚBearerToken.create_token$  s÷   € ð ˜6Ó!Ü�MŠMð Vä,ô.ô 2:¸$¿/¹/×1JÑ1J�T—_‘_ WÔ-ÐPT×P_ÑP_ˆ
à'Ôð !×0Ñ0°Ó9Ø$Ø"ñ
ˆð �>‰>Ñ%Ø ŸX™X g§n¡nÓ5ˆE�'‰NæØ×%×%Ø×.Ñ.×CÑCÀG×LÑLØ)0×)>Ñ)>��oÒ&à)-×)EÑ)EÀgÓ)N��oÑ&à�‰�W×.Ñ.×4°"Ô5Ü˜5Ó!Ð!r   c                 ód   • [        U5      nU R                  R                  X!R                  U5      $ )r�   )r‘   r©   Úvalidate_bearer_tokenr/   )r   r€   rZ   s      r   rŸ   ÚBearerToken.validate_requestK  s0   € ô
 & gÓ.ˆØ×%Ñ%×;Ñ;Ø—>‘> 7ó,ð 	,r   c                 ó¢   • UR                   R                  SS5      R                  S5      S   R                  5       S:X  a  gUR                  b  gg)r�   rE   rC   r³   r   r�   é	   é   )r_   r   rŽ   rH   rw   rž   s     r   r£   ÚBearerToken.estimate_typeT  sK   € ð
 �?‰?×Ñ˜°Ó3×9Ñ9¸#Ó>¸qÑA×GÑGÓIÈXÓUØØ×!Ñ!Ñ-Øàr   )r¬   r«   r©   rª   )NNNNr¥   )
r8   r9   r:   r;   r¦   r   r»   rŸ   r£   r=   rz   r   r   r¨   r¨     s(   † ð€Ið
 @DØ:>ô-ô%"òN,õ
r   r¨   )NNNrC   r@   Nr   r   )rC   r¥   )Ú__doc__rI   rX   r´   Úbinasciir   Úurllib.parser   Úoauthlibr   Úoauthlib.commonr   r   rC   r	   Údictr   ru   rx   r{   r}   r‚   r‰   r‘   r“   r¨   rz   r   r   Ú<module>rÊ      s‡   ðñó Û Û Ý Ý !å ß ?å ô*7�$ô *7ð\ "Ø#Ø ØØ&2Ø"&ØôgòT?ôô 
?ô#ò"ò÷(Lñ Lô*I�)õ Ir   