o
    ‘¸õa)  ã                   @   s†   d Z ddlZddlZddlZddlmZ ddlmZ ddlm	Z	m
Z
 ddlmZ dd	lmZ dd
lmZ e e¡ZG dd„ de	ƒZdS )zð
oauthlib.oauth2.rfc6749.endpoint.metadata
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

An implementation of the `OAuth 2.0 Authorization Server Metadata`.

.. _`OAuth 2.0 Authorization Server Metadata`: https://tools.ietf.org/html/rfc8414
é    Né   )Úgrant_typesé   )ÚAuthorizationEndpoint)ÚBaseEndpointÚcatch_errors_and_unavailability)ÚIntrospectEndpoint)ÚRevocationEndpoint)ÚTokenEndpointc                   @   sb   e Zd ZdZi dfdd„Ze		ddd„ƒZdd
d„Zdd„ Zdd„ Z	dd„ Z
dd„ Zdd„ ZdS )ÚMetadataEndpointa½  OAuth2.0 Authorization Server Metadata endpoint.

   This specification generalizes the metadata format defined by
   `OpenID Connect Discovery 1.0` in a way that is compatible
   with OpenID Connect Discovery while being applicable to a wider set
   of OAuth 2.0 use cases.  This is intentionally parallel to the way
   that OAuth 2.0 Dynamic Client Registration Protocol [`RFC7591`_]
   generalized the dynamic client registration mechanisms defined by
   OpenID Connect Dynamic Client Registration 1.0
   in a way that is compatible with it.

   .. _`OpenID Connect Discovery 1.0`: https://openid.net/specs/openid-connect-discovery-1_0.html
   .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
   Tc                 C   sP   t |tƒsJ ‚|D ]	}t |tƒsJ ‚q	t | ¡ || _|| _|| _|  ¡ | _d S )N)	Ú
isinstanceÚdictr   Ú__init__Úraise_errorsÚ	endpointsÚinitial_claimsÚvalidate_metadata_serverÚclaims)Úselfr   r   r   Úendpoint© r   úL/usr/lib/python3/dist-packages/oauthlib/oauth2/rfc6749/endpoints/metadata.pyr   (   s   
zMetadataEndpoint.__init__ÚGETNc                 C   s   dddœ}|t  | j¡dfS )z!Create metadata response
        zapplication/jsonÚ*)zContent-TypezAccess-Control-Allow-OriginéÈ   )ÚjsonÚdumpsr   )r   ÚuriÚhttp_methodÚbodyÚheadersr   r   r   Úcreate_metadata_response3   s   þz)MetadataEndpoint.create_metadata_responseFc                 C   s  | j sd S ||vr|rtd |¡ƒ‚d S |rE||  d¡s'td ||| ¡ƒ‚d|| v s9d|| v s9d|| v rCtd ||| ¡ƒ‚d S |rZ||  d¡sXtd	 ||| ¡ƒ‚d S |r„t|| tƒsmtd
 ||| ¡ƒ‚|| D ]}t|tƒsƒtd ||| |¡ƒ‚qqd S d S )Nzkey {} is a mandatory metadata.Úhttpszkey {}: {} must be an HTTPS URLú?ú&ú#z8key {}: {} must not contain query or fragment componentsÚhttpzkey {}: {} must be an URLzkey {}: {} must be an Arrayz/array {}: {} must contains only string (not {}))r   Ú
ValueErrorÚformatÚ
startswithr   ÚlistÚstr)r   ÚarrayÚkeyÚis_requiredÚis_listÚis_urlÚ	is_issuerÚelemr   r   r   Úvalidate_metadata>   s2   ÿ$ÿÿ
ÿüz"MetadataEndpoint.validate_metadatac                 C   sX   | j  |j  ¡ ¡ | dddg¡ | j|ddd� | j|ddd� | j|dddd� d	S )
zõ
        If the token endpoint is used in the grant type, the value of this
        parameter MUST be the same as the value of the "grant_type"
        parameter passed to the token endpoint defined in the grant type
        definition.
        Ú%token_endpoint_auth_methods_supportedÚclient_secret_postÚclient_secret_basicT©r/   Ú0token_endpoint_auth_signing_alg_values_supportedÚtoken_endpoint©r.   r0   N)Ú_grant_typesÚextendÚkeysÚ
setdefaultr3   ©r   r   r   r   r   r   Úvalidate_metadata_tokenW   s
   z(MetadataEndpoint.validate_metadata_tokenc                 C   sØ   |  dttdd„ |j ¡ ƒƒ¡ |  dddg¡ d|d v r$| j d¡ | j|dd	d	d
� | j|dd	d� d|d v ra|jd }t|t	j
ƒsNt|dƒrN|j}|  dt|j ¡ ƒ¡ | j|dd	d� | j|dd	d	d� d S )NÚresponse_types_supportedc                 S   s   | dkS )NÚnoner   )Úxr   r   r   Ú<lambda>g   s    zBMetadataEndpoint.validate_metadata_authorization.<locals>.<lambda>Úresponse_modes_supportedÚqueryÚfragmentÚtokenÚimplicitT)r.   r/   r7   ÚcodeÚdefault_grantÚ code_challenge_methods_supportedÚauthorization_endpointr:   )r>   r*   ÚfilterÚ_response_typesr=   r;   Úappendr3   r   r   ÚAuthorizationCodeGrantÚhasattrrK   Ú_code_challenge_methods)r   r   r   Ú
code_grantr   r   r   Úvalidate_metadata_authorizatione   s"   ÿ
ÿz0MetadataEndpoint.validate_metadata_authorizationc                 C   óF   |  dddg¡ | j|ddd� | j|ddd� | j|dddd� d S )	NÚ*revocation_endpoint_auth_methods_supportedr5   r6   Tr7   Ú5revocation_endpoint_auth_signing_alg_values_supportedÚrevocation_endpointr:   ©r>   r3   r?   r   r   r   Úvalidate_metadata_revocation|   ó   ÿz-MetadataEndpoint.validate_metadata_revocationc                 C   rV   )	NÚ-introspection_endpoint_auth_methods_supportedr5   r6   Tr7   Ú8introspection_endpoint_auth_signing_alg_values_supportedÚintrospection_endpointr:   rZ   r?   r   r   r   Úvalidate_metadata_introspection„   r\   z0MetadataEndpoint.validate_metadata_introspectionc                 C   s
  t  | j¡}| j|dddd� | j|ddd� | j|ddd� | j|ddd� | j|d	dd� | j|d
dd� | j|ddd� g | _| jD ].}t|tƒrR|  ||¡ t|t	ƒr]|  
||¡ t|tƒrh|  ||¡ t|tƒrs|  ||¡ qE| d| j¡ | j|ddd� |S )a¬	  
        Authorization servers can have metadata describing their
        configuration.  The following authorization server metadata values
        are used by this specification. More details can be found in
        `RFC8414 section 2`_ :

       issuer
          REQUIRED

       authorization_endpoint
          URL of the authorization server's authorization endpoint
          [`RFC6749#Authorization`_].  This is REQUIRED unless no grant types are supported
          that use the authorization endpoint.

       token_endpoint
          URL of the authorization server's token endpoint [`RFC6749#Token`_].  This
          is REQUIRED unless only the implicit grant type is supported.

       scopes_supported
          RECOMMENDED.

       response_types_supported
          REQUIRED.

       Other OPTIONAL fields:
          jwks_uri,
          registration_endpoint,
          response_modes_supported

       grant_types_supported
          OPTIONAL.  JSON array containing a list of the OAuth 2.0 grant
          type values that this authorization server supports.  The array
          values used are the same as those used with the "grant_types"
          parameter defined by "OAuth 2.0 Dynamic Client Registration
          Protocol" [`RFC7591`_].  If omitted, the default value is
          "["authorization_code", "implicit"]".

       token_endpoint_auth_methods_supported

       token_endpoint_auth_signing_alg_values_supported

       service_documentation

       ui_locales_supported

       op_policy_uri

       op_tos_uri

       revocation_endpoint

       revocation_endpoint_auth_methods_supported

       revocation_endpoint_auth_signing_alg_values_supported

       introspection_endpoint

       introspection_endpoint_auth_methods_supported

       introspection_endpoint_auth_signing_alg_values_supported

       code_challenge_methods_supported

       Additional authorization server metadata parameters MAY also be used.
       Some are defined by other specifications, such as OpenID Connect
       Discovery 1.0 [`OpenID.Discovery`_].

        .. _`RFC8414 section 2`: https://tools.ietf.org/html/rfc8414#section-2
        .. _`RFC6749#Authorization`: https://tools.ietf.org/html/rfc6749#section-3.1
        .. _`RFC6749#Token`: https://tools.ietf.org/html/rfc6749#section-3.2
        .. _`RFC7591`: https://tools.ietf.org/html/rfc7591
        .. _`OpenID.Discovery`: https://openid.net/specs/openid-connect-discovery-1_0.html
        ÚissuerT)r.   r1   Újwks_uri)r0   Úscopes_supportedr7   Úservice_documentationÚui_locales_supportedÚop_policy_uriÚ
op_tos_uriÚgrant_types_supported)ÚcopyÚdeepcopyr   r3   r;   r   r   r
   r@   r   rU   r	   r[   r   r`   r>   r?   r   r   r   r   Œ   s,   J




€z)MetadataEndpoint.validate_metadata_server)r   NN)FFFF)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r!   r3   r@   rU   r[   r`   r   r   r   r   r   r      s    ÿ

r   )rn   ri   r   ÚloggingÚ r   Úauthorizationr   Úbaser   r   Ú
introspectr   Ú
revocationr	   rH   r
   Ú	getLoggerrk   Úlogr   r   r   r   r   Ú<module>   s    
