ó
    ych>)  ã                   óª   • S r SSKrSSKrSSKrSSKJrJr  SSKJr  SSK	J
r
Jr  SSKJr  SS	KJr  SS
KJr  \R$                  " \5      r " S S\
5      rg)zð
oauthlib.oauth2.rfc6749.endpoint.metadata
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

An implementation of the `OAuth 2.0 Authorization Server Metadata`.

.. _`OAuth 2.0 Authorization Server Metadata`: https://tools.ietf.org/html/rfc8414
é    Né   )Úgrant_typesÚutilsé   )ÚAuthorizationEndpoint)ÚBaseEndpointÚcatch_errors_and_unavailability)ÚIntrospectEndpoint)ÚRevocationEndpoint)ÚTokenEndpointc                   óf   • \ rS rSrSr0 S4S jr\  SS j5       rSS jrS r	S	 r
S
 rS rS rSrg)ÚMetadataEndpointé   aœ  OAuth2.0 Authorization Server Metadata endpoint.

This specification generalizes the metadata format defined by
`OpenID Connect Discovery 1.0` in a way that is compatible
with OpenID Connect Discovery while being applicable to a wider set
of OAuth 2.0 use cases.  This is intentionally parallel to the way
that OAuth 2.0 Dynamic Client Registration Protocol [`RFC7591`_]
generalized the dynamic client registration mechanisms defined by
OpenID Connect Dynamic Client Registration 1.0
in a way that is compatible with it.

.. _`OpenID Connect Discovery 1.0`: https://openid.net/specs/openid-connect-discovery-1_0.html
.. _`RFC7591`: https://tools.ietf.org/html/rfc7591
Tc                 óì   • [        U[        5      (       d   eU H  n[        U[        5      (       a  M   e   [        R                  " U 5        X0l        Xl        X l        U R                  5       U l        g )N)	Ú
isinstanceÚdictr   Ú__init__Úraise_errorsÚ	endpointsÚinitial_claimsÚvalidate_metadata_serverÚclaims)Úselfr   r   r   Úendpoints        Ús/var/www/djangovue.mamus.xyz/django/venv/lib/python3.13/site-packages/oauthlib/oauth2/rfc6749/endpoints/metadata.pyr   ÚMetadataEndpoint.__init__(   sc   € Ü˜&¤$×'Ñ'Ð'Ð'Û!ˆHÜ˜h¬×5Ó5Ð5Ð5ñ "ô 	×Ò˜dÔ#Ø(ÔØ"ŒØ$ÔØ×3Ñ3Ó5ˆ�ó    Nc                 óR   • SSS.nU[         R                  " U R                  5      S4$ )z!Create metadata response
        zapplication/jsonÚ*)zContent-TypezAccess-Control-Allow-OriginéÈ   )ÚjsonÚdumpsr   )r   ÚuriÚhttp_methodÚbodyÚheaderss        r   Úcreate_metadata_responseÚ)MetadataEndpoint.create_metadata_response3   s-   € ð /Ø+.ñ
ˆð œŸ
š
 4§;¡;Ó/°Ð4Ð4r   c                 óÒ  • U R                   (       d  g X!;  a"  U(       a  [        SR                  U5      5      eg U(       ap  [        R                  " X   5      (       d  [        SR                  X!U   5      5      eSX   ;   d  SX   ;   d  SX   ;   a  [        SR                  X!U   5      5      eg U(       a6  X   R                  S5      (       d  [        SR                  X!U   5      5      eg U(       as  [        X   [        5      (       d  [        S	R                  X!U   5      5      eX    H6  n[        U[        5      (       a  M  [        S
R                  X!U   U5      5      e   g g )Nzkey {} is a mandatory metadata.zkey {}: {} must be an HTTPS URLÚ?Ú&Ú#z8key {}: {} must not contain query or fragment componentsÚhttpzkey {}: {} must be an URLzkey {}: {} must be an Arrayz/array {}: {} must contains only string (not {}))	r   Ú
ValueErrorÚformatr   Úis_secure_transportÚ
startswithr   ÚlistÚstr)r   ÚarrayÚkeyÚis_requiredÚis_listÚis_urlÚ	is_issuerÚelems           r   Úvalidate_metadataÚ"MetadataEndpoint.validate_metadata>   sN  € Ø× × ØàÓÞÜ Ð!B×!IÑ!IÈ#Ó!NÓOÐOð ö Ü×,Ò,¨U©Z×8Ñ8Ü Ð!B×!IÑ!IÈ#ÐUXÉzÓ!ZÓ[Ð[Ø�e‘jÓ  C¨5©:Ó$5¸ÀÁ
Ó9JÜ Ð![×!bÑ!bÐcfÐnqÑhrÓ!sÓtÐtð :Kö Ø‘:×(Ñ(¨×0Ñ0Ü Ð!<×!CÑ!CÀCÈsÉÓ!TÓUÐUð 1ö Ü˜e™j¬$×/Ñ/Ü Ð!>×!EÑ!EÀcÐQTÉ:Ó!VÓWÐWØœ
�Ü! $¬×,Ó,Ü$Ð%V×%]Ñ%]Ð^aÐilÑcmÐosÓ%tÓuÐuò #ð r   c                 óú   • U R                   R                  UR                   R                  5       5        UR                  SSS/5        U R	                  USSS9  U R	                  USSS9  U R	                  USSSS9  g	)
zÍ
If the token endpoint is used in the grant type, the value of this
parameter MUST be the same as the value of the "grant_type"
parameter passed to the token endpoint defined in the grant type
definition.
Ú%token_endpoint_auth_methods_supportedÚclient_secret_postÚclient_secret_basicT©r7   Ú0token_endpoint_auth_signing_alg_values_supportedÚtoken_endpoint©r6   r8   N)Ú_grant_typesÚextendÚkeysÚ
setdefaultr;   ©r   r   r   s      r   Úvalidate_metadata_tokenÚ(MetadataEndpoint.validate_metadata_tokenW   s†   € ð 	×Ñ× Ñ  ×!6Ñ!6×!;Ñ!;Ó!=Ô>Ø×ÑÐAÐDXÐZoÐCpÔqà×Ñ˜vÐ'NÐX\ÐÑ]Ø×Ñ˜vÐ'YÐcgÐÑhØ×Ñ˜vÐ'7ÀTÐRVÐÒWr   c           
      óŠ  • UR                  S[        [        S UR                  R	                  5       5      5      5        UR                  SSS/5        SUS   ;   a  U R
                  R                  S5        U R                  USSSS	9  U R                  USSS
9  SUS   ;   a�  UR                  S   n[        U[        R                  5      (       d  [        US5      (       a  UR                  nUR                  S[        UR                  R	                  5       5      5        U R                  USSS
9  U R                  USSSS9  g )NÚresponse_types_supportedc                 ó   • U S:g  $ )NÚnone© )Úxs    r   Ú<lambda>ÚBMetadataEndpoint.validate_metadata_authorization.<locals>.<lambda>g   s   € °°V²r   Úresponse_modes_supportedÚqueryÚfragmentÚtokenÚimplicitT)r6   r7   rA   ÚcodeÚdefault_grantÚ code_challenge_methods_supportedÚauthorization_endpointrD   )rH   r2   ÚfilterÚ_response_typesrG   rE   Úappendr;   r   r   ÚAuthorizationCodeGrantÚhasattrrZ   Ú_code_challenge_methods)r   r   r   Ú
code_grants       r   Úvalidate_metadata_authorizationÚ0MetadataEndpoint.validate_metadata_authorizatione   s@  € Ø×ÑÐ4ÜœvÑ&;¸X×=UÑ=U×=ZÑ=ZÓ=\Ó]Ó^ô	`à×ÑÐ4°wÀ
Ð6KÔLð
 �fÐ7Ñ8Ó8Ø×Ñ×$Ñ$ ZÔ0à×Ñ˜vÐ'AÈtÐ]aÐÑbØ×Ñ˜vÐ'AÈ4ÐÑPØ�VÐ6Ñ7Ó7Ø!×1Ñ1°&Ñ9ˆJÜ˜j¬+×*LÑ*L×MÑMÔRYÐZdÐfu×RvÑRvØ'×5Ñ5�
à×ÑÐ@Ü" :×#EÑ#E×#JÑ#JÓ#LÓMôOà×"Ñ" 6Ð+MÐW[Ð"Ñ\Ø×Ñ˜vÐ'?ÈTÐZ^ÐÒ_r   c                 ó”   • UR                  SSS/5        U R                  USSS9  U R                  USSS9  U R                  USSSS9  g )	NÚ*revocation_endpoint_auth_methods_supportedr?   r@   TrA   Ú5revocation_endpoint_auth_signing_alg_values_supportedÚrevocation_endpointrD   ©rH   r;   rI   s      r   Úvalidate_metadata_revocationÚ-MetadataEndpoint.validate_metadata_revocation|   sf   € Ø×ÑÐFØ/Ð1FÐGô	Ið 	×Ñ˜vÐ'SÐ]aÐÑbØ×Ñ˜vÐ'^ÐhlÐÑmØ×Ñ˜vÐ'<È$ÐW[ÐÒ\r   c                 ó”   • UR                  SSS/5        U R                  USSS9  U R                  USSS9  U R                  USSSS9  g )	NÚ-introspection_endpoint_auth_methods_supportedr?   r@   TrA   Ú8introspection_endpoint_auth_signing_alg_values_supportedÚintrospection_endpointrD   rj   rI   s      r   Úvalidate_metadata_introspectionÚ0MetadataEndpoint.validate_metadata_introspection„   sf   € Ø×ÑÐIØ/Ð1FÐGô	Ið 	×Ñ˜vÐ'VÐ`dÐÑeØ×Ñ˜vÐ'aÐkoÐÑpØ×Ñ˜vÐ'?ÈTÐZ^ÐÒ_r   c                 óø  • [         R                  " U R                  5      nU R                  USSSS9  U R                  USSS9  U R                  USSS9  U R                  USSS9  U R                  US	SS9  U R                  US
SS9  U R                  USSS9  / U l        U R
                   H�  n[        U[        5      (       a  U R                  X5        [        U[        5      (       a  U R                  X5        [        U[        5      (       a  U R                  X5        [        U[        5      (       d  MŒ  U R                  X5        MŸ     UR                  SU R                  5        U R                  USSS9  U$ )aN  
 Authorization servers can have metadata describing their
 configuration.  The following authorization server metadata values
 are used by this specification. More details can be found in
 `RFC8414 section 2`_ :

issuer
   REQUIRED

authorization_endpoint
   URL of the authorization server's authorization endpoint
   [`RFC6749#Authorization`_].  This is REQUIRED unless no grant types are supported
   that use the authorization endpoint.

token_endpoint
   URL of the authorization server's token endpoint [`RFC6749#Token`_].  This
   is REQUIRED unless only the implicit grant type is supported.

scopes_supported
   RECOMMENDED.

response_types_supported
   REQUIRED.

Other OPTIONAL fields:
   jwks_uri,
   registration_endpoint,
   response_modes_supported

grant_types_supported
   OPTIONAL.  JSON array containing a list of the OAuth 2.0 grant
   type values that this authorization server supports.  The array
   values used are the same as those used with the "grant_types"
   parameter defined by "OAuth 2.0 Dynamic Client Registration
   Protocol" [`RFC7591`_].  If omitted, the default value is
   "["authorization_code", "implicit"]".

token_endpoint_auth_methods_supported

token_endpoint_auth_signing_alg_values_supported

service_documentation

ui_locales_supported

op_policy_uri

op_tos_uri

revocation_endpoint

revocation_endpoint_auth_methods_supported

revocation_endpoint_auth_signing_alg_values_supported

introspection_endpoint

introspection_endpoint_auth_methods_supported

introspection_endpoint_auth_signing_alg_values_supported

code_challenge_methods_supported

Additional authorization server metadata parameters MAY also be used.
Some are defined by other specifications, such as OpenID Connect
Discovery 1.0 [`OpenID.Discovery`_].

 .. _`RFC8414 section 2`: https://tools.ietf.org/html/rfc8414#section-2
 .. _`RFC6749#Authorization`: https://tools.ietf.org/html/rfc6749#section-3.1
 .. _`RFC6749#Token`: https://tools.ietf.org/html/rfc6749#section-3.2
 .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
 .. _`OpenID.Discovery`: https://openid.net/specs/openid-connect-discovery-1_0.html
 ÚissuerT)r6   r9   Újwks_uri)r8   Úscopes_supportedrA   Úservice_documentationÚui_locales_supportedÚop_policy_uriÚ
op_tos_uriÚgrant_types_supported)ÚcopyÚdeepcopyr   r;   rE   r   r   r   rJ   r   rd   r   rk   r
   rq   rH   rI   s      r   r   Ú)MetadataEndpoint.validate_metadata_serverŒ   sj  € ôT —’˜t×2Ñ2Ó3ˆØ×Ñ˜v x¸TÈTÐÑRØ×Ñ˜v z¸$ÐÑ?Ø×Ñ˜vÐ'9À4ÐÑHØ×Ñ˜vÐ'>ÀtÐÑLØ×Ñ˜vÐ'=ÀtÐÑLØ×Ñ˜v ¸tÐÑDØ×Ñ˜v |¸DÐÑAàˆÔØŸœˆHÜ˜(¤M×2Ñ2Ø×,Ñ,¨VÔ>Ü˜(Ô$9×:Ñ:Ø×4Ñ4°VÔFÜ˜(Ô$6×7Ñ7Ø×1Ñ1°&ÔCÜ˜(Ô$6×7Ó7Ø×4Ñ4°VÖFñ 'ð 	×ÑÐ1°4×3DÑ3DÔEØ×Ñ˜vÐ'>ÈÐÑMØˆr   )rE   r   r   r   r   )ÚGETNN)FFFF)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__r   r	   r'   r;   rJ   rd   rk   rq   r   Ú__static_attributes__rP   r   r   r   r      sQ   † ñð *,¸$ô 	6ð %ØDHØ)-ó5ó %ð5ôvò2Xò`ò.]ò`õbr   r   )r„   r|   r!   ÚloggingÚ r   r   Úauthorizationr   Úbaser   r	   Ú
introspectr
   Ú
revocationr   rW   r   Ú	getLoggerr€   Úlogr   rP   r   r   Ú<module>rŽ      sE   ðñó Û Û ç !Ý 0ß ?Ý *Ý *Ý  à×Ò˜Ó!€ôW�|õ Wr   