o
    �¨Êh†T  ã                   @   sˆ   d dl mZ d dlZd dlmZmZ d dlmZmZ d dlm	Z	 d dlm
Z
mZ d dlZe e¡ZG dd„ deƒZG d	d
„ d
ejƒZdS )é    )Úunicode_literalsN)Úgenerate_tokenÚ	urldecode)ÚWebApplicationClientÚInsecureTransportError)ÚLegacyApplicationClient)ÚTokenExpiredErrorÚis_secure_transportc                       s   e Zd Z‡ fdd„Z‡  ZS )ÚTokenUpdatedc                    s   t t| ƒ ¡  || _d S ©N)Úsuperr
   Ú__init__Útoken)Úselfr   ©Ú	__class__© úR/var/www/html/env/lib/python3.10/site-packages/requests_oauthlib/oauth2_session.pyr      s   
zTokenUpdated.__init__)Ú__name__Ú
__module__Ú__qualname__r   Ú__classcell__r   r   r   r   r
      s    r
   c                       s"  e Zd ZdZ									d$‡ fdd„	Zdd„ Zedd„ ƒZejd	d„ ƒZej	d
d„ ƒZedd„ ƒZ
e
jdd„ ƒZ
edd„ ƒZejdd„ ƒZej	dd„ ƒZedd„ ƒZd%dd„Z														d&dd„Zdd„ Z							d'dd„Z					d(‡ fd d!„	Zd"d#„ Z‡  ZS ))ÚOAuth2Sessiona*  Versatile OAuth 2 extension to :class:`requests.Session`.

    Supports any grant type adhering to :class:`oauthlib.oauth2.Client` spec
    including the four core OAuth 2 grants.

    Can be used to create authorization urls, fetch tokens and access protected
    resources using the :class:`requests.Session` interface you are used to.

    - :class:`oauthlib.oauth2.WebApplicationClient` (default): Authorization Code Grant
    - :class:`oauthlib.oauth2.MobileApplicationClient`: Implicit Grant
    - :class:`oauthlib.oauth2.LegacyApplicationClient`: Password Credentials Grant
    - :class:`oauthlib.oauth2.BackendApplicationClient`: Client Credentials Grant

    Note that the only time you will be using Implicit Grant from python is if
    you are driving a user agent able to obtain URL fragments.
    Nc
                    s†   t t| ƒjdi |
¤Ž |pt||d�| _|pi | _|| _|| _|p"t| _	|| _
|| _|p-i | _|	| _dd„ | _tƒ tƒ tƒ dœ| _dS )aH  Construct a new OAuth 2 client session.

        :param client_id: Client id obtained during registration
        :param client: :class:`oauthlib.oauth2.Client` to be used. Default is
                       WebApplicationClient which is useful for any
                       hosted application but not mobile or desktop.
        :param scope: List of scopes you wish to request access to
        :param redirect_uri: Redirect URI you registered as callback
        :param token: Token dictionary, must include access_token
                      and token_type.
        :param state: State string used to prevent CSRF. This will be given
                      when creating the authorization url and must be supplied
                      when parsing the authorization response.
                      Can be either a string or a no argument callable.
        :auto_refresh_url: Refresh token endpoint URL, must be HTTPS. Supply
                           this if you wish the client to automatically refresh
                           your access tokens.
        :auto_refresh_kwargs: Extra arguments to pass to the refresh token
                              endpoint.
        :token_updater: Method with one argument, token, to be used to update
                        your token database on automatic token refresh. If not
                        set a TokenUpdated warning will be raised when a token
                        has been refreshed. This warning will carry the token
                        in its token argument.
        :param kwargs: Arguments to pass to the Session constructor.
        )r   c                 S   s   | S r   r   )Úrr   r   r   Ú<lambda>Z   s    z(OAuth2Session.__init__.<locals>.<lambda>)Úaccess_token_responseÚrefresh_token_responseÚprotected_requestNr   )r   r   r   r   Ú_clientr   ÚscopeÚredirect_urir   ÚstateÚ_stateÚauto_refresh_urlÚauto_refresh_kwargsÚtoken_updaterÚauthÚsetÚcompliance_hook)r   Ú	client_idÚclientr#   r$   r   r    r   r!   r%   Úkwargsr   r   r   r   &   s   '



ýzOAuth2Session.__init__c                 C   sN   z|   ¡ | _t d| j¡ W | jS  ty&   | j | _t d| j¡ Y | jS w )z6Generates a state string to be used in authorizations.zGenerated new state %s.z&Re-using previously supplied state %s.)r!   r"   ÚlogÚdebugÚ	TypeError©r   r   r   r   Ú	new_stated   s   
ýýzOAuth2Session.new_statec                 C   ó   t | jdd ƒS )Nr)   ©Úgetattrr   r/   r   r   r   r)   n   ó   zOAuth2Session.client_idc                 C   ó   || j _d S r   ©r   r)   ©r   Úvaluer   r   r   r)   r   ó   c                 C   ó
   | j `d S r   r6   r/   r   r   r   r)   v   ó   
c                 C   r1   )Nr   r2   r/   r   r   r   r   z   r4   zOAuth2Session.tokenc                 C   s   || j _| j  |¡ d S r   )r   r   Úpopulate_token_attributesr7   r   r   r   r   ~   s   c                 C   r1   )NÚaccess_tokenr2   r/   r   r   r   r=   ƒ   r4   zOAuth2Session.access_tokenc                 C   r5   r   ©r   r=   r7   r   r   r   r=   ‡   r9   c                 C   r:   r   r>   r/   r   r   r   r=   ‹   r;   c                 C   s
   t | jƒS )a€  Boolean that indicates whether this session has an OAuth token
        or not. If `self.authorized` is True, you can reasonably expect
        OAuth-protected requests to the resource to succeed. If
        `self.authorized` is False, you need the user to go through the OAuth
        authentication dance before OAuth-protected requests to the resource
        will succeed.
        )Úboolr=   r/   r   r   r   Ú
authorized�   s   
	zOAuth2Session.authorizedc                 K   s0   |p|   ¡ }| jj|f| j| j|dœ|¤Ž|fS )aF  Form an authorization URL.

        :param url: Authorization endpoint url, must be HTTPS.
        :param state: An optional state string for CSRF protection. If not
                      given it will be generated for you.
        :param kwargs: Extra parameters to include.
        :return: authorization_url, state
        )r    r   r!   )r0   r   Úprepare_request_urir    r   )r   Úurlr!   r+   r   r   r   Úauthorization_urlš   s   	ÿüûøzOAuth2Session.authorization_urlÚ ÚPOSTFTc              
   K   sh  t |ƒstƒ ‚|s|r| jj|| jd� | jj}n|s+t| jtƒr+| jj}|s+tdƒ‚t| jt	ƒrA|du r9tdƒ‚|du rAtdƒ‚|durI||d< |durQ||d< |dur\|du r[d}n|d	urz| j
}|rzt d
|¡ |durq|nd}tj ||¡}|r„|dur„||d< | jjd!||| j|dœ|¤Ž}|p™dddœ}i | _i }| ¡ dkr²tt|ƒƒ||	r¯dnd< n| ¡ dkrÁtt|ƒƒ|d< ntdƒ‚| jd!|||
||||dœ|¤Ž}t d|j¡ t d|jj¡ t d|jj¡ t d|jj¡ t d|j|j¡ t dt| jd ƒ¡ | jd D ]}t d|¡ ||ƒ}�q| jj|j| jd� | jj| _t d | j¡ | jS )"aÞ	  Generic method for fetching an access token from the token endpoint.

        If you are using the MobileApplicationClient you will want to use
        `token_from_fragment` instead of `fetch_token`.

        The current implementation enforces the RFC guidelines.

        :param token_url: Token endpoint URL, must use HTTPS.
        :param code: Authorization code (used by WebApplicationClients).
        :param authorization_response: Authorization response URL, the callback
                                       URL of the request back to you. Used by
                                       WebApplicationClients instead of code.
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by `requests`.
        :param username: Username required by LegacyApplicationClients to appear
                         in the request body.
        :param password: Password required by LegacyApplicationClients to appear
                         in the request body.
        :param method: The HTTP method used to make the request. Defaults
                       to POST, but may also be GET. Other methods should
                       be added as needed.
        :param force_querystring: If True, force the request body to be sent
            in the querystring instead.
        :param timeout: Timeout of the request in seconds.
        :param headers: Dict to default request headers with.
        :param verify: Verify SSL certificate.
        :param proxies: The `proxies` argument is passed onto `requests`.
        :param include_client_id: Should the request body include the
                                  `client_id` parameter. Default is `None`,
                                  which will attempt to autodetect. This can be
                                  forced to always include (True) or never
                                  include (False).
        :param client_secret: The `client_secret` paired to the `client_id`.
                              This is generally required unless provided in the
                              `auth` tuple. If the value is `None`, it will be
                              omitted from the request, however if the value is
                              an empty string, an empty string will be sent.
        :param kwargs: Extra parameters to include in the token request.
        :return: A token dict
        ©r!   z?Please supply either code or authorization_response parameters.NzQ`LegacyApplicationClient` requires both the `username` and `password` parameters.zGThe required parameter `username` was supplied, but `password` was not.ÚusernameÚpasswordFTzIEncoding `client_id` "%s" with `client_secret` as Basic auth credentials.rD   Úclient_secret)ÚcodeÚbodyr    Úinclude_client_idúapplication/jsonú/application/x-www-form-urlencoded;charset=UTF-8©ÚAcceptzContent-TyperE   ÚparamsÚdataÚGETz%The method kwarg must be POST or GET.)ÚmethodrB   ÚtimeoutÚheadersr&   ÚverifyÚproxiesz0Request to fetch token completed with status %s.zRequest url was %szRequest headers were %szRequest body was %sú(Response headers were %s and content %s.ú!Invoking %d token response hooks.r   úInvoking hook %s.©r   zObtained token %s.r   ) r	   r   r   Úparse_request_uri_responser"   rJ   Ú
isinstancer   Ú
ValueErrorr   r)   r,   r-   Úrequestsr&   ÚHTTPBasicAuthÚprepare_request_bodyr    r   ÚupperÚdictr   ÚrequestÚstatus_coderB   rV   rK   ÚtextÚlenr(   Úparse_request_body_responser   )r   Ú	token_urlrJ   Úauthorization_responserK   r&   rG   rH   rT   Úforce_querystringrU   rV   rW   rX   rL   rI   r+   r)   Úrequest_kwargsr   Úhookr   r   r   Úfetch_token¯   s´   <ÿ
ÿÿÿ€ýüûþÿùøþ
zOAuth2Session.fetch_tokenc                 C   s"   | j j|| jd� | j j| _| jS )z¼Parse token from the URI fragment, used by MobileApplicationClients.

        :param authorization_response: The full URL of the redirect back to you
        :return: A token dict
        rF   )r   r]   r"   r   )r   rk   r   r   r   Útoken_from_fragmentm  s
   ÿ
z!OAuth2Session.token_from_fragmentc	              
   K   s4  |st dƒ‚t|ƒstƒ ‚|p| j d¡}t d| j¡ |	 | j¡ | j	j
d||| jdœ|	¤Ž}t d|¡ |du r?ddd	œ}| j|tt|ƒƒ||||d
|d�}
t d|
j¡ t d|
j|
j¡ t dt| jd ƒ¡ | jd D ]}t d|¡ ||
ƒ}
qp| j	j|
j| jd�| _d| jvr—t d¡ || jd< | jS )aô  Fetch a new access token using a refresh token.

        :param token_url: The token endpoint, must be HTTPS.
        :param refresh_token: The refresh_token to use.
        :param body: Optional application/x-www-form-urlencoded body to add the
                     include in the token request. Prefer kwargs over body.
        :param auth: An auth tuple or method as accepted by `requests`.
        :param timeout: Timeout of the request in seconds.
        :param headers: A dict of headers to be used by `requests`.
        :param verify: Verify SSL certificate.
        :param proxies: The `proxies` argument will be passed to `requests`.
        :param kwargs: Extra parameters to include in the token request.
        :return: A token dict
        z'No token endpoint set for auto_refresh.Úrefresh_tokenz*Adding auto refresh key word arguments %s.)rK   rq   r   z&Prepared refresh token request body %sNrM   rN   rO   T)rR   r&   rU   rV   rW   Úwithhold_tokenrX   z2Request to refresh token completed with status %s.rY   rZ   r   r[   r\   z)No new refresh token given. Re-using old.r   )r_   r	   r   r   Úgetr,   r-   r$   Úupdater   Úprepare_refresh_bodyr   Úpostrd   r   rf   rV   rg   rh   r(   ri   )r   rj   rq   rK   r&   rU   rV   rW   rX   r+   r   rn   r   r   r   rq   y  sV   ÿÿÿþ
ø
þ



zOAuth2Session.refresh_tokenc              	      sŒ  t |ƒstƒ ‚| jr¢|s¢t dt| jd ƒ¡ | jd D ]}	t d|	¡ |	|||ƒ\}}}qt d| j¡ z| jj||||d�\}}}W n] t	y¡   | j
ržt d| j
¡ | dd¡}
|rp|rp|
du rpt d	|¡ tj ||¡}
| j| j
fd|
i|¤Ž}| jršt d
|| j¡ |  |¡ | jj||||d�\}}}nt|ƒ‚‚ Y nw t d||¡ t d||¡ t d|¡ tt| ƒj||f||dœ|¤ŽS )z<Intercept all requests and add the OAuth 2 token if present.z-Invoking %d protected resource request hooks.r   r[   zAdding token %s to request.)Úhttp_methodrK   rV   z1Auto refresh is set, attempting to refresh at %s.r&   NzEEncoding client_id "%s" with client_secret as Basic auth credentials.zUpdating token to %s using %s.z"Requesting url %s using method %s.z Supplying headers %s and data %sz&Passing through key word arguments %s.)rV   rR   )r	   r   r   r,   r-   rh   r(   r   Ú	add_tokenr   r#   Úpopr`   r&   ra   rq   r%   r
   r   r   re   )r   rT   rB   rR   rV   rr   r)   rI   r+   rn   r&   r   r   r   r   re   Ä  sr   
þÿþþÿÿÿÿ
ÿúé
ÿÿÿzOAuth2Session.requestc                 C   s,   || j vrtd|| j ƒ‚| j |  |¡ dS )a�  Register a hook for request/response tweaking.

        Available hooks are:
            access_token_response invoked before token parsing.
            refresh_token_response invoked before refresh token parsing.
            protected_request invoked before making a request.

        If you find a new hook is needed please send a GitHub PR request
        or open an issue.
        zHook type %s is not in %s.N)r(   r_   Úadd)r   Ú	hook_typern   r   r   r   Úregister_compliance_hook  s
   
ÿz&OAuth2Session.register_compliance_hook)	NNNNNNNNNr   )NNrD   NNNrE   FNNTNNN)NrD   NNNTN)NNFNN)r   r   r   Ú__doc__r   r0   Úpropertyr)   ÚsetterÚdeleterr   r=   r@   rC   ro   rp   rq   re   r|   r   r   r   r   r   r      s€    ö>












ð ?
÷OøCr   )Ú
__future__r   ÚloggingÚoauthlib.commonr   r   Úoauthlib.oauth2r   r   r   r   r	   r`   Ú	getLoggerr   r,   ÚWarningr
   ÚSessionr   r   r   r   r   Ú<module>   s    
