Ë
    ~ºßh>)  ã                   óª   — d Z ddlZddlZddlZddlmZmZ ddlmZ ddl	m
Z
mZ ddlmZ dd	lmZ dd
lmZ  ej$                  e«      Z G d„ de
«      Zy)zð
oauthlib.oauth2.rfc6749.endpoint.metadata
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

An implementation of the `OAuth 2.0 Authorization Server Metadata`.

.. _`OAuth 2.0 Authorization Server Metadata`: https://tools.ietf.org/html/rfc8414
é    Né   )Úgrant_typesÚutilsé   )ÚAuthorizationEndpoint)ÚBaseEndpointÚcatch_errors_and_unavailability)ÚIntrospectEndpoint)ÚRevocationEndpoint)ÚTokenEndpointc                   óX   — e Zd ZdZi dfd„Ze	 	 dd„«       Zdd„Zd„ Zd„ Z	d	„ Z
d
„ Zd„ Zy)ÚMetadataEndpointa½  OAuth2.0 Authorization Server Metadata endpoint.

   This specification generalizes the metadata format defined by
   `OpenID Connect Discovery 1.0` in a way that is compatible
   with OpenID Connect Discovery while being applicable to a wider set
   of OAuth 2.0 use cases.  This is intentionally parallel to the way
   that OAuth 2.0 Dynamic Client Registration Protocol [`RFC7591`_]
   generalized the dynamic client registration mechanisms defined by
   OpenID Connect Dynamic Client Registration 1.0
   in a way that is compatible with it.

   .. _`OpenID Connect Discovery 1.0`: https://openid.net/specs/openid-connect-discovery-1_0.html
   .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
   Tc                 óØ   — t        |t        «      sJ ‚|D ]  }t        |t        «      rŒJ ‚ t        j                  | «       || _        || _        || _        | j                  «       | _        y )N)	Ú
isinstanceÚdictr   Ú__init__Úraise_errorsÚ	endpointsÚinitial_claimsÚvalidate_metadata_serverÚclaims)Úselfr   r   r   Úendpoints        úe/var/www/html/python/myenv/lib/python3.12/site-packages/oauthlib/oauth2/rfc6749/endpoints/metadata.pyr   zMetadataEndpoint.__init__(   sh   € Ü˜&¤$Ô'Ð'Ð'Ø!ò 	6ˆHÜ˜h¬Õ5Ð5Ð5ð	6ô 	×Ñ˜dÔ#Ø(ˆÔØ"ˆŒØ$ˆÔØ×3Ñ3Ó5ˆ�ó    Nc                 óP   — dddœ}|t        j                  | j                  «      dfS )z!Create metadata response
        zapplication/jsonÚ*)zContent-TypezAccess-Control-Allow-OriginéÈ   )ÚjsonÚdumpsr   )r   ÚuriÚhttp_methodÚbodyÚheaderss        r   Úcreate_metadata_responsez)MetadataEndpoint.create_metadata_response3   s-   € ð /Ø+.ñ
ˆð œŸ
™
 4§;¡;Ó/°Ð4Ð4r   c                 ó|  — | j                   sy ||vr|rt        dj                  |«      «      ‚y |rjt        j                  ||   «      st        dj                  |||   «      «      ‚d||   v sd||   v sd||   v rt        dj                  |||   «      «      ‚y |r3||   j                  d«      st        dj                  |||   «      «      ‚y |rkt        ||   t        «      st        d	j                  |||   «      «      ‚||   D ]1  }t        |t        «      rŒt        d
j                  |||   |«      «      ‚ y y )Nzkey {} is a mandatory metadata.zkey {}: {} must be an HTTPS URLú?ú&ú#z8key {}: {} must not contain query or fragment componentsÚhttpzkey {}: {} must be an URLzkey {}: {} must be an Arrayz/array {}: {} must contains only string (not {}))	r   Ú
ValueErrorÚformatr   Úis_secure_transportÚ
startswithr   ÚlistÚstr)r   ÚarrayÚkeyÚis_requiredÚis_listÚis_urlÚ	is_issuerÚelems           r   Úvalidate_metadataz"MetadataEndpoint.validate_metadata>   se  € Ø× Ò Øà�eÑÙÜ Ð!B×!IÑ!IÈ#Ó!NÓOÐOð ñ Ü×,Ñ,¨U°3©ZÔ8Ü Ð!B×!IÑ!IÈ#ÈuÐUXÉzÓ!ZÓ[Ð[Ø�e˜C‘jÑ  C¨5°©:Ñ$5¸ÀÀcÁ
Ñ9JÜ Ð![×!bÑ!bÐcfÐhmÐnqÑhrÓ!sÓtÐtð :Kñ Ø˜‘:×(Ñ(¨Ô0Ü Ð!<×!CÑ!CÀCÈÈsÉÓ!TÓUÐUð 1ñ Ü˜e C™j¬$Ô/Ü Ð!>×!EÑ!EÀcÈ5ÐQTÉ:Ó!VÓWÐWØ˜c™
ò v�Ü! $¬Õ,Ü$Ð%V×%]Ñ%]Ð^aÐchÐilÑcmÐosÓ%tÓuÐuñvð r   c                 ó  — | j                   j                  |j                   j                  «       «       |j                  dddg«       | j	                  |dd¬«       | j	                  |dd¬«       | j	                  |ddd¬«       y	)
zõ
        If the token endpoint is used in the grant type, the value of this
        parameter MUST be the same as the value of the "grant_type"
        parameter passed to the token endpoint defined in the grant type
        definition.
        Ú%token_endpoint_auth_methods_supportedÚclient_secret_postÚclient_secret_basicT©r4   Ú0token_endpoint_auth_signing_alg_values_supportedÚtoken_endpoint©r3   r5   N)Ú_grant_typesÚextendÚkeysÚ
setdefaultr8   ©r   r   r   s      r   Úvalidate_metadata_tokenz(MetadataEndpoint.validate_metadata_tokenW   s†   € ð 	×Ñ× Ñ  ×!6Ñ!6×!;Ñ!;Ó!=Ô>Ø×ÑÐAÐDXÐZoÐCpÔqà×Ñ˜vÐ'NÐX\ÐÔ]Ø×Ñ˜vÐ'YÐcgÐÔhØ×Ñ˜vÐ'7ÀTÐRVÐÕWr   c           
      ó†  — |j                  dt        t        d„ |j                  j	                  «       «      «      «       |j                  dddg«       d|d   v r| j
                  j                  d«       | j                  |ddd¬	«       | j                  |dd¬
«       d|d   v rˆ|j                  d   }t        |t        j                  «      st        |d«      r|j                  }|j                  dt        |j                  j	                  «       «      «       | j                  |dd¬
«       | j                  |ddd¬«       y )NÚresponse_types_supportedc                 ó   — | dk7  S )NÚnone© )Úxs    r   ú<lambda>zBMetadataEndpoint.validate_metadata_authorization.<locals>.<lambda>g   s
   € °°V±€ r   Úresponse_modes_supportedÚqueryÚfragmentÚtokenÚimplicitT)r3   r4   r=   ÚcodeÚdefault_grantÚ code_challenge_methods_supportedÚauthorization_endpointr@   )rD   r/   ÚfilterÚ_response_typesrC   rA   Úappendr8   r   r   ÚAuthorizationCodeGrantÚhasattrrT   Ú_code_challenge_methods)r   r   r   Ú
code_grants       r   Úvalidate_metadata_authorizationz0MetadataEndpoint.validate_metadata_authorizatione   s:  € Ø×ÑÐ4ÜœvÑ&;¸X×=UÑ=U×=ZÑ=ZÓ=\Ó]Ó^ô	`à×ÑÐ4°wÀ
Ð6KÔLð
 �fÐ7Ñ8Ñ8Ø×Ñ×$Ñ$ ZÔ0à×Ñ˜vÐ'AÈtÐ]aÐÔbØ×Ñ˜vÐ'AÈ4ÐÔPØ�VÐ6Ñ7Ñ7Ø!×1Ñ1°&Ñ9ˆJÜ˜j¬+×*LÑ*LÔMÔRYÐZdÐfuÔRvØ'×5Ñ5�
à×ÑÐ@Ü" :×#EÑ#E×#JÑ#JÓ#LÓMôOà×"Ñ" 6Ð+MÐW[Ð"Ô\Ø×Ñ˜vÐ'?ÈTÐZ^ÐÕ_r   c                 ó¦   — |j                  dddg«       | j                  |dd¬«       | j                  |dd¬«       | j                  |ddd¬«       y )	NÚ*revocation_endpoint_auth_methods_supportedr;   r<   Tr=   Ú5revocation_endpoint_auth_signing_alg_values_supportedÚrevocation_endpointr@   ©rD   r8   rE   s      r   Úvalidate_metadata_revocationz-MetadataEndpoint.validate_metadata_revocation|   sf   € Ø×ÑÐFØ/Ð1FÐGô	Ið 	×Ñ˜vÐ'SÐ]aÐÔbØ×Ñ˜vÐ'^ÐhlÐÔmØ×Ñ˜vÐ'<È$ÐW[ÐÕ\r   c                 ó¦   — |j                  dddg«       | j                  |dd¬«       | j                  |dd¬«       | j                  |ddd¬«       y )	NÚ-introspection_endpoint_auth_methods_supportedr;   r<   Tr=   Ú8introspection_endpoint_auth_signing_alg_values_supportedÚintrospection_endpointr@   rc   rE   s      r   Úvalidate_metadata_introspectionz0MetadataEndpoint.validate_metadata_introspection„   sf   € Ø×ÑÐIØ/Ð1FÐGô	Ið 	×Ñ˜vÐ'VÐ`dÐÔeØ×Ñ˜vÐ'aÐkoÐÔpØ×Ñ˜vÐ'?ÈTÐZ^ÐÕ_r   c                 ó   — t        j                  | j                  «      }| j                  |ddd¬«       | j                  |dd¬«       | j                  |dd¬«       | j                  |dd¬«       | j                  |d	d¬«       | j                  |d
d¬«       | j                  |dd¬«       g | _        | j
                  D ]‹  }t        |t        «      r| j                  ||«       t        |t        «      r| j                  ||«       t        |t        «      r| j                  ||«       t        |t        «      sŒz| j                  ||«       Œ� |j                  d| j                  «       | j                  |dd¬«       |S )a¬	  
        Authorization servers can have metadata describing their
        configuration.  The following authorization server metadata values
        are used by this specification. More details can be found in
        `RFC8414 section 2`_ :

       issuer
          REQUIRED

       authorization_endpoint
          URL of the authorization server's authorization endpoint
          [`RFC6749#Authorization`_].  This is REQUIRED unless no grant types are supported
          that use the authorization endpoint.

       token_endpoint
          URL of the authorization server's token endpoint [`RFC6749#Token`_].  This
          is REQUIRED unless only the implicit grant type is supported.

       scopes_supported
          RECOMMENDED.

       response_types_supported
          REQUIRED.

       Other OPTIONAL fields:
          jwks_uri,
          registration_endpoint,
          response_modes_supported

       grant_types_supported
          OPTIONAL.  JSON array containing a list of the OAuth 2.0 grant
          type values that this authorization server supports.  The array
          values used are the same as those used with the "grant_types"
          parameter defined by "OAuth 2.0 Dynamic Client Registration
          Protocol" [`RFC7591`_].  If omitted, the default value is
          "["authorization_code", "implicit"]".

       token_endpoint_auth_methods_supported

       token_endpoint_auth_signing_alg_values_supported

       service_documentation

       ui_locales_supported

       op_policy_uri

       op_tos_uri

       revocation_endpoint

       revocation_endpoint_auth_methods_supported

       revocation_endpoint_auth_signing_alg_values_supported

       introspection_endpoint

       introspection_endpoint_auth_methods_supported

       introspection_endpoint_auth_signing_alg_values_supported

       code_challenge_methods_supported

       Additional authorization server metadata parameters MAY also be used.
       Some are defined by other specifications, such as OpenID Connect
       Discovery 1.0 [`OpenID.Discovery`_].

        .. _`RFC8414 section 2`: https://tools.ietf.org/html/rfc8414#section-2
        .. _`RFC6749#Authorization`: https://tools.ietf.org/html/rfc6749#section-3.1
        .. _`RFC6749#Token`: https://tools.ietf.org/html/rfc6749#section-3.2
        .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
        .. _`OpenID.Discovery`: https://openid.net/specs/openid-connect-discovery-1_0.html
        ÚissuerT)r3   r6   Újwks_uri)r5   Úscopes_supportedr=   Úservice_documentationÚui_locales_supportedÚop_policy_uriÚ
op_tos_uriÚgrant_types_supported)ÚcopyÚdeepcopyr   r8   rA   r   r   r   rF   r   r^   r   rd   r
   ri   rD   rE   s      r   r   z)MetadataEndpoint.validate_metadata_serverŒ   sm  € ôT —‘˜t×2Ñ2Ó3ˆØ×Ñ˜v x¸TÈTÐÔRØ×Ñ˜v z¸$ÐÔ?Ø×Ñ˜vÐ'9À4ÐÔHØ×Ñ˜vÐ'>ÀtÐÔLØ×Ñ˜vÐ'=ÀtÐÔLØ×Ñ˜v ¸tÐÔDØ×Ñ˜v |¸DÐÔAàˆÔØŸ™ò 	GˆHÜ˜(¤MÔ2Ø×,Ñ,¨V°XÔ>Ü˜(Ô$9Ô:Ø×4Ñ4°V¸XÔFÜ˜(Ô$6Ô7Ø×1Ñ1°&¸(ÔCÜ˜(Ô$6Õ7Ø×4Ñ4°V¸XÕFð	Gð 	×ÑÐ1°4×3DÑ3DÔEØ×Ñ˜vÐ'>ÈÐÔMØˆr   )ÚGETNN)FFFF)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r	   r%   r8   rF   r^   rd   ri   r   rK   r   r   r   r      sQ   „ ñð *,¸$ó 	6ð %ØDHØ)-ò5ó %ð5óvò2Xò`ò.]ò`óbr   r   )ry   rs   r   ÚloggingÚ r   r   Úauthorizationr   Úbaser   r	   Ú
introspectr
   Ú
revocationr   rQ   r   Ú	getLoggerrv   Úlogr   rK   r   r   ú<module>r‚      sG   ðñó Û Û ç !Ý 0ß ?Ý *Ý *Ý  à€g×Ñ˜Ó!€ôW�|õ Wr   