Ë
    ¯`Úip/  ã                   óh  — d dl m Z mZ d dlmZmZmZmZmZ d dlm	Z	 d dl
mZ d dlmZ d dlmZ d dlmZ dd	lmZmZ dd
lmZ ddlmZ ddlmZmZ ddlmZmZmZm Z m!Z! erddl"m#Z#  edee«      Z$ G d„ d«      Z% G d„ d«      Z& G d„ de&e%«      Z' G d„ de%«      Z( G d„ de&e%«      Z) G d„ de%«      Z*y)é    )ÚdatetimeÚ	timedelta)ÚTYPE_CHECKINGÚAnyÚDictÚOptionalÚTypeVar)Úuuid4)Úsettings)ÚAbstractBaseUser)Úimport_string)Úgettext_lazyé   )ÚTokenBackendErrorÚ
TokenError)Ú	TokenUser)Úapi_settings)ÚBlacklistedTokenÚOutstandingToken)Úaware_utcnowÚdatetime_from_epochÚdatetime_to_epochÚformat_lazyÚget_md5_hash_password)ÚTokenBackendÚAuthUserc            	       ó�  — e Zd ZU dZdZee   ed<   dZee	   ed<   d#ded    de
ddfd„Zdefd	„Zd
efd„Zd
ededdfd„Zd
eddfd„Zd
edefd„Zd$d
edee   defd„Zdefd„Zd%d„Zd%d„Zd%d„Z	 	 	 d&dedee   dee	   ddfd„Zd'dedee   ddfd„Z	 d(dedee   ddfd„Zededd fd„«       ZdZed   ed <   ed)d!„«       Z d)d"„Z!y)*ÚTokenzb
    A class which validates and wraps an existing JWT or can be used to build a
    new JWT.
    NÚ
token_typeÚlifetimeÚtokenÚverifyÚreturnc                 ó0  — | j                   �| j                  €t        t        d«      «      ‚|| _        t        «       | _        |�=| j                  «       }	 |j                  ||¬«      | _	        |r| j                  «        yyt        j                  | j                   i| _	        | j                  | j                  | j                  ¬«       | j                  | j                  ¬«       | j!                  «        y# t        $ r t        t        d«      «      ‚w xY w)z´
        !!!! IMPORTANT !!!! MUST raise a TokenError with a user-facing error
        message if the given token is invalid, expired, or otherwise not safe
        to use.
        Nz,Cannot create token with no type or lifetime)r"   zToken is invalid or expired©Ú	from_timer    )Úat_time)r   r    r   Ú_r!   r   Úcurrent_timeÚget_token_backendÚdecodeÚpayloadr   r"   r   ÚTOKEN_TYPE_CLAIMÚset_expÚset_iatÚset_jti)Úselfr!   r"   Útoken_backends       úV/var/www/html/acx/venv/lib/python3.12/site-packages/rest_framework_simplejwt/tokens.pyÚ__init__zToken.__init__%   sö   € ð �?‰?Ð" d§m¡mÐ&;ÜœQÐMÓNÓOÐOàˆŒ
Ü(›NˆÔð Ðà ×2Ñ2Ó4ˆMðCØ,×3Ñ3°EÀ&Ð3ÓI�”ñ Ø—‘•ð ô )×9Ñ9¸4¿?¹?ÐKˆDŒLð �L‰L 4×#4Ñ#4¸t¿}¹}ˆLÔMØ�L‰L ×!2Ñ!2ˆLÔ3ð �L‰L�Nøô %ò CÜ ¤Ð#@Ó!AÓBÐBðCús   ÁC7 Ã7Dc                 ó,   — t        | j                  «      S ©N)Úreprr,   ©r1   s    r3   Ú__repr__zToken.__repr__I   s   € Ü�D—L‘LÓ!Ð!ó    Úkeyc                 ó    — | j                   |   S r6   ©r,   ©r1   r;   s     r3   Ú__getitem__zToken.__getitem__L   s   € Ø�|‰|˜CÑ Ð r:   Úvaluec                 ó"   — || j                   |<   y r6   r=   )r1   r;   r@   s      r3   Ú__setitem__zToken.__setitem__O   s   € Ø!ˆ�‰�SÒr:   c                 ó   — | j                   |= y r6   r=   r>   s     r3   Ú__delitem__zToken.__delitem__R   s   € Ø�L‰L˜Ñr:   c                 ó   — || j                   v S r6   r=   r>   s     r3   Ú__contains__zToken.__contains__U   s   € Ø�d—l‘lÐ"Ð"r:   Údefaultc                 ó:   — | j                   j                  ||«      S r6   )r,   Úget)r1   r;   rG   s      r3   rI   z	Token.getX   s   € Ø�|‰|×Ñ  WÓ-Ð-r:   c                 óT   — | j                  «       j                  | j                  «      S )zG
        Signs and returns a token as a base64 encoded string.
        )r*   Úencoder,   r8   s    r3   Ú__str__zToken.__str__[   s"   € ð ×%Ñ%Ó'×.Ñ.¨t¯|©|Ó<Ð<r:   c                 óæ   — | j                  «        t        j                  �0t        j                  | j                  vrt	        t        d«      «      ‚t        j                  �| j                  «        yy)zè
        Performs additional validation steps which were not performed when this
        token was decoded.  This method is part of the "public" API to indicate
        the intention that it may be overridden in subclasses.
        NzToken has no id)Ú	check_expr   Ú	JTI_CLAIMr,   r   r(   r-   Úverify_token_typer8   s    r3   r"   zToken.verifya   s\   € ð 	�‰Ôô ×"Ñ"Ð.Ü×&Ñ&¨d¯l©lÑ:äœQÐ0Ó1Ó2Ð2ä×(Ñ(Ð4Ø×"Ñ"Õ$ð 5r:   c                 óÈ   — 	 | j                   t        j                     }| j                  |k7  rt	        t        d«      «      ‚y# t        $ r t	        t        d«      «      ‚w xY w)zY
        Ensures that the token type claim is present and has the correct value.
        zToken has no typezToken has wrong typeN)r,   r   r-   ÚKeyErrorr   r(   r   )r1   r   s     r3   rP   zToken.verify_token_typey   sa   € ð	5ØŸ™¤l×&CÑ&CÑDˆJð �?‰?˜jÒ(ÜœQÐ5Ó6Ó7Ð7ð )øô ò 	5ÜœQÐ2Ó3Ó4Ð4ð	5ús   ‚A ÁA!c                 ób   — t        «       j                  | j                  t        j                  <   y)a  
        Populates the configured jti claim of a token with a string where there
        is a negligible probability that the same string will be chosen at a
        later time.

        See here:
        https://tools.ietf.org/html/rfc7519#section-4.1.7
        N)r
   Úhexr,   r   rO   r8   s    r3   r0   zToken.set_jti…   s   € ô 05«w¯{©{ˆ�‰”\×+Ñ+Ò,r:   Úclaimr&   c                 ór   — |€| j                   }|€| j                  }t        ||z   «      | j                  |<   y)z†
        Updates the expiration time of a token.

        See here:
        https://tools.ietf.org/html/rfc7519#section-4.1.4
        N)r)   r    r   r,   )r1   rU   r&   r    s       r3   r.   zToken.set_exp�   s<   € ð ÐØ×)Ñ)ˆIàÐØ—}‘}ˆHä/°	¸HÑ0DÓEˆ�‰�UÒr:   r'   c                 óP   — |€| j                   }t        |«      | j                  |<   y)zŽ
        Updates the time at which the token was issued.

        See here:
        https://tools.ietf.org/html/rfc7519#section-4.1.6
        N)r)   r   r,   )r1   rU   r'   s      r3   r/   zToken.set_iat¤   s'   € ð ˆ?Ø×'Ñ'ˆGä/°Ó8ˆ�‰�UÒr:   r)   c                 ó4  — |€| j                   }	 | j                  |   }t        |«      }| j                  «       j                  «       }|||z
  k  rt        t	        t        d«      |«      «      ‚y# t        $ r t        t	        t        d«      |«      «      ‚w xY w)zÑ
        Checks whether a timestamp value in the given claim has passed (since
        the given datetime value in `current_time`).  Raises a TokenError with
        a user-facing error message if so.
        NzToken has no '{}' claimzToken '{}' claim has expired)	r)   r,   rR   r   r   r(   r   r*   Ú
get_leeway)r1   rU   r)   Úclaim_valueÚ
claim_timeÚleeways         r3   rN   zToken.check_exp°   s¡   € ð ÐØ×,Ñ,ˆLð	OØŸ,™, uÑ-ˆKô )¨Ó5ˆ
Ø×'Ñ'Ó)×4Ñ4Ó6ˆØ˜¨Ñ.Ò.Üœ[¬Ð+IÓ)JÈEÓRÓSÐSð /øô ò 	OÜœ[¬Ð+DÓ)EÀuÓMÓNÐNð	Oús   �A/ Á/(BÚuserc                 ó  — t        |t        j                  «      }t        |t        «      st        |«      } | «       }||t        j                  <   t        j                  r&t        |j                  «      |t        j                  <   |S )zŽ
        Returns an authorization token for the given user that will be provided
        after authenticating the user's credentials.
        )Úgetattrr   ÚUSER_ID_FIELDÚ
isinstanceÚintÚstrÚUSER_ID_CLAIMÚCHECK_REVOKE_TOKENr   ÚpasswordÚREVOKE_TOKEN_CLAIM)Úclsr]   Úuser_idr!   s       r3   Úfor_userzToken.for_userÅ   sl   € ô ˜$¤× :Ñ :Ó;ˆÜ˜'¤3Ô'Ü˜'“lˆGá“ˆØ,3ˆŒl×(Ñ(Ñ)ä×*Ò*Ü5JØ—‘ó6ˆE”,×1Ñ1Ñ2ð ˆr:   r   Ú_token_backendc                 óR   — | j                   €t        d«      | _         | j                   S )Nz,rest_framework_simplejwt.state.token_backend)rk   r   r8   s    r3   r2   zToken.token_backendÛ   s,   € à×ÑÐ&Ü"/Ø>ó#ˆDÔð ×"Ñ"Ð"r:   c                 ó   — | j                   S r6   )r2   r8   s    r3   r*   zToken.get_token_backendã   s   € à×!Ñ!Ð!r:   )NTr6   ©r#   N)ÚexpNN)ÚiatN)ro   N)r#   r   )"Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   rc   Ú__annotations__r    r   Úboolr4   r9   r?   r   rB   rD   rF   rI   rL   r"   rP   r0   r   r.   r/   rN   Úclassmethodr   rj   rk   Úpropertyr2   r*   © r:   r3   r   r      s´  … ñð
 !%€J�˜‘Ó$Ø$(€Hˆh�yÑ!Ó(ñ"˜h wÑ/ð "Àð "ÐPTó "ðH"˜#ó "ð!˜só !ð"˜sð "¨3ð "°4ó "ð˜sð  tó ð# ð #¨ó #ñ.�sð . X¨c¡]ð .¸có .ð=˜ó =ó%ó0
8ó	;ð Ø(,Ø(,ñ	FàðFð ˜HÑ%ðFð ˜9Ñ%ð	Fð
 
óFñ(
9˜Sð 
9°8¸HÑ3Eð 
9ÐQUó 
9ð FJñTØðTØ08¸Ñ0BðTà	óTð* ð˜Hð ¨ò ó ðð& 04€N�H˜^Ñ,Ó3àò#ó ð#ô"r:   r   c                   ó�   ‡ — e Zd ZU dZeeef   ed<   dej                  v r#d
ˆ fd„Z
d
d„Zdefd„Zededefˆ fd	„«       Zˆ xZS ˆ xZS )ÚBlacklistMixina  
    If the `rest_framework_simplejwt.token_blacklist` app was configured to be
    used, tokens created from `BlacklistMixin` subclasses will insert
    themselves into an outstanding token list and also check for their
    membership in a token blacklist.
    r,   z(rest_framework_simplejwt.token_blacklistr#   c                 óD   •— | j                  «        t        ‰| �  |i |¤Ž y r6   )Úcheck_blacklistÚsuperr"   ©r1   ÚargsÚkwargsÚ	__class__s      €r3   r"   zBlacklistMixin.verifyô   s    ø€ Ø× Ñ Ô"ä‰G‰N˜DÐ+ FÓ+r:   c                 óÂ   — | j                   t        j                     }t        j                  j                  |¬«      j                  «       rt        t        d«      «      ‚y)zy
            Checks if this token is present in the token blacklist.  Raises
            `TokenError` if so.
            )Ú
token__jtizToken is blacklistedN)	r,   r   rO   r   ÚobjectsÚfilterÚexistsr   r(   )r1   Újtis     r3   r}   zBlacklistMixin.check_blacklistù   sO   € ð
 —,‘,œ|×5Ñ5Ñ6ˆCä×'Ñ'×.Ñ.¸#Ð.Ó>×EÑEÔGÜ ¤Ð#9Ó!:Ó;Ð;ð Hr:   c                 ó  — | j                   t        j                     }| j                   d   }t        j                  j                  |t        | «      t        |«      dœ¬«      \  }}t        j                  j                  |¬«      S )z€
            Ensures this token is included in the outstanding token list and
            adds it to the blacklist.
            ro   )r!   Ú
expires_at)rˆ   Údefaults)r!   )	r,   r   rO   r   r…   Úget_or_createrc   r   r   )r1   rˆ   ro   r!   r(   s        r3   Ú	blacklistzBlacklistMixin.blacklist  sz   € ð
 —,‘,œ|×5Ñ5Ñ6ˆCØ—,‘,˜uÑ%ˆCô (×/Ñ/×=Ñ=Øä  ›YÜ"5°cÓ":ñð >ó ‰HˆE�1ô $×+Ñ+×9Ñ9ÀÐ9ÓFÐFr:   r]   c           	      óÖ   •— t         ‰| �  |«      }|t        j                     }|d   }t        j
                  j                  ||t        |«      |j                  t        |«      ¬«       |S )zH
            Adds this token to the outstanding token list.
            ro   )r]   rˆ   r!   Ú
created_atrŠ   )
r~   rj   r   rO   r   r…   Úcreaterc   r)   r   )rh   r]   r!   rˆ   ro   r‚   s        €r3   rj   zBlacklistMixin.for_user  sk   ø€ ô
 ‘GÑ$ TÓ*ˆEàœ×.Ñ.Ñ/ˆCØ˜‘,ˆCä×$Ñ$×+Ñ+ØØÜ˜%“jØ ×-Ñ-Ü.¨sÓ3ð ,ô ð ˆLr:   rn   )rq   rr   rs   rt   r   rc   r   ru   r   ÚINSTALLED_APPSr"   r}   r   r�   rw   r   r   rj   Ú__classcell__©r‚   s   @r3   r{   r{   è   sh   ø… ñð �#�s�(‰^Óà1°X×5LÑ5LÑLõ	,ó
	<ð	GÐ/ó 	Gð& 
ð	 ð 	¨Uô 	ó 
ô	óK Mr:   r{   c                   ó<   ‡ — e Zd ZdZej
                  Zdˆ fd„Zˆ xZS )ÚSlidingTokenÚslidingc                 ó²   •— t        ‰| �  |i |¤Ž | j                  €;| j                  t        j
                  | j                  t        j                  ¬«       y y )Nr%   )r~   r4   r!   r.   r   ÚSLIDING_TOKEN_REFRESH_EXP_CLAIMr)   ÚSLIDING_TOKEN_REFRESH_LIFETIMEr   s      €r3   r4   zSlidingToken.__init__/  sP   ø€ Ü‰Ñ˜$Ð) &Ò)à�:‰:Ðà�L‰LÜ×<Ñ<Ø×+Ñ+Ü%×DÑDð õ ð r:   rn   )	rq   rr   rs   r   r   ÚSLIDING_TOKEN_LIFETIMEr    r4   r’   r“   s   @r3   r•   r•   +  s   ø„ Ø€JØ×2Ñ2€H÷	ñ 	r:   r•   c                   ó(   — e Zd ZdZej
                  Zy)ÚAccessTokenÚaccessN)rq   rr   rs   r   r   ÚACCESS_TOKEN_LIFETIMEr    ry   r:   r3   rœ   rœ   ;  s   „ Ø€JØ×1Ñ1�Hr:   rœ   c                   óv   — e Zd ZdZej
                  Zej                  dej                  dfZ	e
Zede
fd„«       Zy)ÚRefreshTokenÚrefreshro   rˆ   r#   c                 óÎ   — | j                  «       }|j                  | j                  ¬«       | j                  }| j                  j                  «       D ]  \  }}||v rŒ|||<   Œ |S )zá
        Returns an access token created from this refresh token.  Copies all
        claims present in this refresh token to the new access token except
        those claims listed in the `no_copy_claims` attribute.
        )r&   )Úaccess_token_classr.   r)   Úno_copy_claimsr,   Úitems)r1   r�   Úno_copyrU   r@   s        r3   Úaccess_tokenzRefreshToken.access_tokenO  sn   € ð ×(Ñ(Ó*ˆð 	�‰ ×!2Ñ!2ˆÔ3à×%Ñ%ˆØ ŸL™L×.Ñ.Ó0ò 	"‰LˆE�5Ø˜ÑØØ!ˆF�5ŠMð	"ð
 ˆr:   N)rq   rr   rs   r   r   ÚREFRESH_TOKEN_LIFETIMEr    r-   rO   r¤   rœ   r£   rx   r§   ry   r:   r3   r    r    @  sT   „ Ø€JØ×2Ñ2€Hà×%Ñ%Øð
 	×ÑØð	€Nð %Ðàð˜kò ó ñr:   r    c                   ó*   — e Zd ZdZ ed¬«      Zdd„Zy)ÚUntypedTokenÚuntypedr   )ÚsecondsNc                  ó   — y)zæ
        Untyped tokens do not verify the "token_type" claim.  This is useful
        when performing general validation of a token's signature and other
        properties which do not relate to the token's intended use.
        Nry   r8   s    r3   rP   zUntypedToken.verify_token_typek  s   € ð 	r:   rn   )rq   rr   rs   r   r   r    rP   ry   r:   r3   rª   rª   g  s   „ Ø€JÙ Ô#€Hôr:   rª   N)+r   r   Útypingr   r   r   r   r	   Úuuidr
   Údjango.confr   Údjango.contrib.auth.modelsr   Údjango.utils.module_loadingr   Údjango.utils.translationr   r(   Ú
exceptionsr   r   Úmodelsr   r   Útoken_blacklist.modelsr   r   Úutilsr   r   r   r   r   Úbackendsr   r   r   r{   r•   rœ   r    rª   ry   r:   r3   ú<module>r¹      s™   ðß (ß >Õ >Ý å  Ý 7Ý 5Ý 6ç 5Ý Ý "ß F÷õ ñ Ý&á�:Ð/°Ó;€÷I"ñ I"÷X@ñ @ôF�> 5ô ô 2�%ô 2ô
$�> 5ô $ôN
�5õ 
r:   