o
    y¨ÊhZ)  ã                   @   s¢   d Z ddlmZmZ ddlZddlZddlZddlmZ ddl	m
Z
mZ ddlmZ dd	lmZ dd
lmZ ddlmZ ddlmZ e e¡ZG dd„ de
ƒZdS )zð
oauthlib.oauth2.rfc6749.endpoint.metadata
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

An implementation of the `OAuth 2.0 Authorization Server Metadata`.

.. _`OAuth 2.0 Authorization Server Metadata`: https://tools.ietf.org/html/rfc8414
é    )Úabsolute_importÚunicode_literalsNé   )Úunicode_typeé   )ÚBaseEndpointÚcatch_errors_and_unavailability)ÚAuthorizationEndpoint)ÚIntrospectEndpoint)ÚTokenEndpoint)ÚRevocationEndpointé   )Úgrant_typesc                   @   sb   e Zd ZdZi dfdd„Ze		ddd„ƒZdd
d„Zdd„ Zdd„ Z	dd„ Z
dd„ Zdd„ ZdS )ÚMetadataEndpointa½  OAuth2.0 Authorization Server Metadata endpoint.

   This specification generalizes the metadata format defined by
   `OpenID Connect Discovery 1.0` in a way that is compatible
   with OpenID Connect Discovery while being applicable to a wider set
   of OAuth 2.0 use cases.  This is intentionally parallel to the way
   that OAuth 2.0 Dynamic Client Registration Protocol [`RFC7591`_]
   generalized the dynamic client registration mechanisms defined by
   OpenID Connect Dynamic Client Registration 1.0
   in a way that is compatible with it.

   .. _`OpenID Connect Discovery 1.0`: https://openid.net/specs/openid-connect-discovery-1_0.html
   .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
   Tc                 C   sP   t |tƒsJ ‚|D ]	}t |tƒsJ ‚q	t | ¡ || _|| _|| _|  ¡ | _d S )N)	Ú
isinstanceÚdictr   Ú__init__Úraise_errorsÚ	endpointsÚinitial_claimsÚvalidate_metadata_serverÚclaims)Úselfr   r   r   Úendpoint© r   ú\/var/www/html/env/lib/python3.10/site-packages/oauthlib/oauth2/rfc6749/endpoints/metadata.pyr   -   s   
zMetadataEndpoint.__init__ÚGETNc                 C   s   ddi}|t  | j¡dfS )z!Create metadata response
        zContent-Typezapplication/jsonéÈ   )ÚjsonÚdumpsr   )r   ÚuriÚhttp_methodÚbodyÚheadersr   r   r   Úcreate_metadata_response8   s   ÿz)MetadataEndpoint.create_metadata_responseFc                 C   s  | j sd S ||vr|rtd |¡ƒ‚d S |rE||  d¡s'td ||| ¡ƒ‚d|| v s9d|| v s9d|| v rCtd ||| ¡ƒ‚d S |rZ||  d¡sXtd	 ||| ¡ƒ‚d S |r„t|| tƒsmtd
 ||| ¡ƒ‚|| D ]}t|tƒsƒtd ||| |¡ƒ‚qqd S d S )Nzkey {} is a mandatory metadata.Úhttpszkey {}: {} must be an HTTPS URLú?ú&ú#z8key {}: {} must not contain query or fragment componentsÚhttpzkey {}: {} must be an URLzkey {}: {} must be an Arrayz/array {}: {} must contains only string (not {}))r   Ú
ValueErrorÚformatÚ
startswithr   Úlistr   )r   ÚarrayÚkeyÚis_requiredÚis_listÚis_urlÚ	is_issuerÚelemr   r   r   Úvalidate_metadataB   s2   ÿ$ÿÿ
ÿüz"MetadataEndpoint.validate_metadatac                 C   sX   | j  |j  ¡ ¡ | dddg¡ | j|ddd� | j|ddd� | j|dddd� d	S )
zõ
        If the token endpoint is used in the grant type, the value of this
        parameter MUST be the same as the value of the "grant_type"
        parameter passed to the token endpoint defined in the grant type
        definition.
        Ú%token_endpoint_auth_methods_supportedÚclient_secret_postÚclient_secret_basicT©r1   Ú0token_endpoint_auth_signing_alg_values_supportedÚtoken_endpoint©r0   r2   N)Ú_grant_typesÚextendÚkeysÚ
setdefaultr5   ©r   r   r   r   r   r   Úvalidate_metadata_token[   s
   z(MetadataEndpoint.validate_metadata_tokenc                 C   sØ   |  dttdd„ |j ¡ ƒƒ¡ |  dddg¡ d|d v r$| j d¡ | j|dd	d	d
� | j|dd	d� d|d v ra|jd }t|t	j
ƒsNt|dƒrN|j}|  dt|j ¡ ƒ¡ | j|dd	d� | j|dd	d	d� d S )NÚresponse_types_supportedc                 S   s   | dkS )NÚnoner   )Úxr   r   r   Ú<lambda>k   s    zBMetadataEndpoint.validate_metadata_authorization.<locals>.<lambda>Úresponse_modes_supportedÚqueryÚfragmentÚtokenÚimplicitT)r0   r1   r9   ÚcodeÚdefault_grantÚ code_challenge_methods_supportedÚauthorization_endpointr<   )r@   r-   ÚfilterÚ_response_typesr?   r=   Úappendr5   r   r   ÚAuthorizationCodeGrantÚhasattrrM   Ú_code_challenge_methods)r   r   r   Ú
code_grantr   r   r   Úvalidate_metadata_authorizationi   s"   ÿ
ÿz0MetadataEndpoint.validate_metadata_authorizationc                 C   óF   |  dddg¡ | j|ddd� | j|ddd� | j|dddd� d S )	NÚ*revocation_endpoint_auth_methods_supportedr7   r8   Tr9   Ú5revocation_endpoint_auth_signing_alg_values_supportedÚrevocation_endpointr<   ©r@   r5   rA   r   r   r   Úvalidate_metadata_revocation€   ó   ÿz-MetadataEndpoint.validate_metadata_revocationc                 C   rX   )	NÚ-introspection_endpoint_auth_methods_supportedr7   r8   Tr9   Ú8introspection_endpoint_auth_signing_alg_values_supportedÚintrospection_endpointr<   r\   rA   r   r   r   Úvalidate_metadata_introspectionˆ   r^   z0MetadataEndpoint.validate_metadata_introspectionc                 C   s
  t  | j¡}| j|dddd� | j|ddd� | j|ddd� | j|ddd� | j|d	dd� | j|d
dd� | j|ddd� g | _| jD ].}t|tƒrR|  ||¡ t|t	ƒr]|  
||¡ t|tƒrh|  ||¡ t|tƒrs|  ||¡ qE| d| j¡ | j|ddd� |S )a£	  
        Authorization servers can have metadata describing their
        configuration.  The following authorization server metadata values
        are used by this specification. More details can be found in
        `RFC8414 section 2`_ :

       issuer
          REQUIRED

       authorization_endpoint
          URL of the authorization server's authorization endpoint
          [`RFC6749#Authorization`_].  This is REQUIRED unless no grant types are supported
          that use the authorization endpoint.

       token_endpoint
          URL of the authorization server's token endpoint [`RFC6749#Token`_].  This
          is REQUIRED unless only the implicit grant type is supported.

       scopes_supported
          RECOMMENDED.

       response_types_supported
          REQUIRED.

       * Other OPTIONAL fields:
       jwks_uri
       registration_endpoint
       response_modes_supported

       grant_types_supported
          OPTIONAL.  JSON array containing a list of the OAuth 2.0 grant
          type values that this authorization server supports.  The array
          values used are the same as those used with the "grant_types"
          parameter defined by "OAuth 2.0 Dynamic Client Registration
          Protocol" [`RFC7591`_].  If omitted, the default value is
          "["authorization_code", "implicit"]".

       token_endpoint_auth_methods_supported

       token_endpoint_auth_signing_alg_values_supported

       service_documentation

       ui_locales_supported

       op_policy_uri

       op_tos_uri

       revocation_endpoint

       revocation_endpoint_auth_methods_supported

       revocation_endpoint_auth_signing_alg_values_supported

       introspection_endpoint

       introspection_endpoint_auth_methods_supported

       introspection_endpoint_auth_signing_alg_values_supported

       code_challenge_methods_supported

       Additional authorization server metadata parameters MAY also be used.
       Some are defined by other specifications, such as OpenID Connect
       Discovery 1.0 [`OpenID.Discovery`_].

        .. _`RFC8414 section 2`: https://tools.ietf.org/html/rfc8414#section-2
        .. _`RFC6749#Authorization`: https://tools.ietf.org/html/rfc6749#section-3.1
        .. _`RFC6749#Token`: https://tools.ietf.org/html/rfc6749#section-3.2
        .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
        .. _`OpenID.Discovery`: https://openid.net/specs/openid-connect-discovery-1_0.html
        ÚissuerT)r0   r3   Újwks_uri)r2   Úscopes_supportedr9   Úservice_documentationÚui_locales_supportedÚop_policy_uriÚ
op_tos_uriÚgrant_types_supported)ÚcopyÚdeepcopyr   r5   r=   r   r   r   rB   r	   rW   r   r]   r
   rb   r@   rA   r   r   r   r   �   s,   J




€z)MetadataEndpoint.validate_metadata_server)r   NN)FFFF)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r$   r5   rB   rW   r]   rb   r   r   r   r   r   r      s    ÿ
	r   )rp   Ú
__future__r   r   rk   r   ÚloggingÚcommonr   Úbaser   r   Úauthorizationr	   Ú
introspectr
   rJ   r   Ú
revocationr   Ú r   Ú	getLoggerrm   Úlogr   r   r   r   r   Ú<module>   s   
