§
    ¢”j—!  ã                  ó¨   — d dl mZ d dlZd dlZd dlmZ d dlmZ d dl	m
Z
 d dlmZmZ ddlmZmZ dd	lmZ dd
lmZmZ ddlmZ  G d„ d¦  «        ZdS )é    )ÚannotationsN)Ú	lru_cache)Ú
SSLContext)ÚAny)Ú	HTTPErrorÚURLErroré   )ÚPyJWKÚPyJWKSet)Údecode_complete)ÚPyJWKClientConnectionErrorÚPyJWKClientError)ÚJWKSetCachec                  ój   — e Zd Z	 	 	 	 	 	 	 d'd(d„Zd)d„Zd*d+d„Zd*d,d„Zd-d „Zd.d#„Ze	d/d&„¦   «         Z
dS )0ÚPyJWKClientFé   Té,  Né   ÚuriÚstrÚ
cache_keysÚboolÚmax_cached_keysÚintÚcache_jwk_setÚlifespanÚfloatÚheadersúdict[str, Any] | NoneÚtimeoutÚssl_contextúSSLContext | Nonec	                ó  — |€i }|| _         d| _        || _        || _        || _        |r.|dk    rt          d|› d�¦  «        ‚t          |¦  «        | _        nd| _        |r' t          |¬¦  «        | j        ¦  «        }	|	| _        dS dS )u—  A client for retrieving signing keys from a JWKS endpoint.

        ``PyJWKClient`` uses a two-tier caching system to avoid unnecessary
        network requests:

        **Tier 1 â€” JWK Set cache** (enabled by default):
        Caches the entire JSON Web Key Set response from the endpoint.
        Controlled by:

        - ``cache_jwk_set``: Set to ``True`` (the default) to enable this
          cache. When enabled, the JWK Set is fetched from the network only
          when the cache is empty or expired.
        - ``lifespan``: Time in seconds before the cached JWK Set expires.
          Defaults to ``300`` (5 minutes). Must be greater than 0.

        **Tier 2 â€” Signing key cache** (disabled by default):
        Caches individual signing keys (looked up by ``kid``) using an LRU
        cache with **no time-based expiration**. Keys are evicted only when
        the cache reaches its maximum size. Controlled by:

        - ``cache_keys``: Set to ``True`` to enable this cache.
          Defaults to ``False``.
        - ``max_cached_keys``: Maximum number of signing keys to keep in
          the LRU cache. Defaults to ``16``.

        :param uri: The URL of the JWKS endpoint.
        :type uri: str
        :param cache_keys: Enable the per-key LRU cache (Tier 2).
        :type cache_keys: bool
        :param max_cached_keys: Max entries in the signing key LRU cache.
        :type max_cached_keys: int
        :param cache_jwk_set: Enable the JWK Set response cache (Tier 1).
        :type cache_jwk_set: bool
        :param lifespan: TTL in seconds for the JWK Set cache.
        :type lifespan: float
        :param headers: Optional HTTP headers to include in requests.
        :type headers: dict or None
        :param timeout: HTTP request timeout in seconds.
        :type timeout: float
        :param ssl_context: Optional SSL context for the request.
        :type ssl_context: ssl.SSLContext or None
        Nr   z/Lifespan must be greater than 0, the input is "ú")Úmaxsize)	r   Újwk_set_cacher   r    r!   r   r   r   Úget_signing_key)
Úselfr   r   r   r   r   r   r    r!   r'   s
             ú^/var/www/finuniver-perm.ru/html/portfolio/venv/lib/python3.11/site-packages/jwt/jwks_client.pyÚ__init__zPyJWKClient.__init__   sÁ   € ðj ˆ?ØˆGØˆŒØ15ˆÔØˆŒØˆŒØ&ˆÔàð 		&ð ˜1Š}ˆ}Ý&ØQÀhÐQÐQÐQñô ð õ "-¨XÑ!6Ô!6ˆDÔÐà!%ˆDÔàð 	3à@�i°Ð@Ñ@Ô@ÀÔAUÑVÔVˆOà#2ˆDÔ Ð Ð ð		3ð 	3ó    Úreturnr   c                óP  — d}	 t           j                             | j        | j        ¬¦  «        }t           j                             || j        | j        ¬¦  «        5 }t          j	        |¦  «        }ddd¦  «         n# 1 swxY w Y   || j
        �| j
                             |¦  «         S S # t          t          f$ rB}t          |t          ¦  «        r|                     ¦   «          t#          d|› d�¦  «        |‚d}~ww xY w# | j
        �| j
                             |¦  «         w w xY w)ae  Fetch the JWK Set from the JWKS endpoint.

        Makes an HTTP request to the configured ``uri`` and returns the
        parsed JSON response. If the JWK Set cache is enabled, the
        response is stored in the cache.

        :returns: The parsed JWK Set as a dictionary.
        :raises PyJWKClientConnectionError: If the HTTP request fails.
        N)Úurlr   )r    Úcontextz'Fail to fetch data from the url, err: "r$   )ÚurllibÚrequestÚRequestr   r   Úurlopenr    r!   ÚjsonÚloadr&   Úputr   ÚTimeoutErrorÚ
isinstancer   Úcloser   )r(   Újwk_setÚrÚresponseÚes        r)   Ú
fetch_datazPyJWKClient.fetch_data_   sz  € ð ˆð	0Ý”×&Ò&¨4¬8¸T¼\Ð&ÑJÔJˆAÝ”×'Ò'Ø˜4œ<°Ô1Að (ñ ô ð .àÝœ) HÑ-Ô-�ð.ð .ð .ñ .ô .ð .ð .ð .ð .ð .ð .øøøð .ð .ð .ð .ð àÔ!Ð-ØÔ"×&Ò& wÑ/Ô/Ð/Ð/ð .øõ �,Ð'ð 	ð 	ð 	Ý˜!�YÑ'Ô'ð Ø—’‘	”	�	Ý,Ø>¸!Ð>Ð>Ð>ñô àðøøøøð	øøøøð Ô!Ð-ØÔ"×&Ò& wÑ/Ô/Ð/Ð/ð .øøøsN   „AB+ ÁA<Á0B+ Á<B Â B+ ÂB ÂB+ ÂD Â+C>Â<=C9Ã9C>Ã>D Ä$D%Úrefreshr   c                óæ   — d}| j         �|s| j                              ¦   «         }|€|                      ¦   «         }t          |t          ¦  «        st          d¦  «        ‚t          j        |¦  «        S )aN  Return the JWK Set, using the cache when available.

        :param refresh: Force a fresh fetch from the endpoint, bypassing
            the cache.
        :type refresh: bool
        :returns: The JWK Set.
        :rtype: PyJWKSet
        :raises PyJWKClientError: If the endpoint does not return a JSON
            object.
        Nz.The JWKS endpoint did not return a JSON object)r&   Úgetr>   r8   Údictr   r   Ú	from_dict)r(   r?   Údatas      r)   Úget_jwk_setzPyJWKClient.get_jwk_set|   sr   € ð ˆØÔÐ)°'Ð)ØÔ%×)Ò)Ñ+Ô+ˆDàˆ<Ø—?’?Ñ$Ô$ˆDå˜$¥Ñ%Ô%ð 	UÝ"Ð#SÑTÔTÐTåÔ! $Ñ'Ô'Ð'r+   úlist[PyJWK]c                ót   — |                       |¦  «        }d„ |j        D ¦   «         }|st          d¦  «        ‚|S )a§  Return all signing keys from the JWK Set.

        Filters the JWK Set to keys whose ``use`` is ``"sig"`` (or
        unspecified) and that have a ``kid``.

        :param refresh: Force a fresh fetch from the endpoint, bypassing
            the cache.
        :type refresh: bool
        :returns: A list of signing keys.
        :rtype: list[PyJWK]
        :raises PyJWKClientError: If no signing keys are found.
        c                ó2   — g | ]}|j         d v ¯|j        ¯|‘ŒS ))ÚsigN)Úpublic_key_useÚkey_id)Ú.0Újwk_set_keys     r)   ú
<listcomp>z0PyJWKClient.get_signing_keys.<locals>.<listcomp>¡   s8   € ð 
ð 
ð 
àØÔ)¨]Ð:Ð:¸{Ô?QÐ:ð à:Ð:Ð:r+   z2The JWKS endpoint did not contain any signing keys)rE   Úkeysr   )r(   r?   r:   Úsigning_keyss       r)   Úget_signing_keyszPyJWKClient.get_signing_keys“   sW   € ð ×"Ò" 7Ñ+Ô+ˆð
ð 
à&œ|ð
ñ 
ô 
ˆð ð 	YÝ"Ð#WÑXÔXÐXàÐr+   Úkidr
   c                óà   — |                       ¦   «         }|                      ||¦  «        }|sA|                       d¬¦  «        }|                      ||¦  «        }|st          d|› d�¦  «        ‚|S )a¡  Return the signing key matching the given ``kid``.

        If no match is found in the current JWK Set, the set is
        refreshed from the endpoint and the lookup is retried once.

        :param kid: The key ID to look up.
        :type kid: str
        :returns: The matching signing key.
        :rtype: PyJWK
        :raises PyJWKClientError: If no matching key is found after
            refreshing.
        T)r?   z,Unable to find a signing key that matches: "r$   )rQ   Ú	match_kidr   )r(   rR   rP   Úsigning_keys       r)   r'   zPyJWKClient.get_signing_key¬   s‰   € ð ×,Ò,Ñ.Ô.ˆØ—n’n \°3Ñ7Ô7ˆàð 	à×0Ò0¸Ð0Ñ>Ô>ˆLØŸ.š.¨°sÑ;Ô;ˆKàð Ý&ØIÀ3ÐIÐIÐIñô ð ð Ðr+   Útokenústr | bytesc                óˆ   — t          |ddi¬¦  «        }|d         }|                      |                     d¦  «        ¦  «        S )aG  Return the signing key for a JWT by reading its ``kid`` header.

        Extracts the ``kid`` from the token's unverified header and
        delegates to :meth:`get_signing_key`.

        :param token: The encoded JWT.
        :type token: str or bytes
        :returns: The matching signing key.
        :rtype: PyJWK
        Úverify_signatureF)ÚoptionsÚheaderrR   )Údecode_tokenr'   rA   )r(   rV   Ú
unverifiedr[   s       r)   Úget_signing_key_from_jwtz$PyJWKClient.get_signing_key_from_jwtÈ   sF   € õ " %Ð2DÀeÐ1LÐMÑMÔMˆ
Ø˜HÔ%ˆØ×#Ò# F§J¢J¨uÑ$5Ô$5Ñ6Ô6Ð6r+   rP   úPyJWK | Nonec                ó2   — d}| D ]}|j         |k    r|} nŒ|S )a7  Find a key in *signing_keys* that matches *kid*.

        :param signing_keys: The list of keys to search.
        :type signing_keys: list[PyJWK]
        :param kid: The key ID to match.
        :type kid: str
        :returns: The matching key, or ``None`` if not found.
        :rtype: PyJWK or None
        N)rK   )rP   rR   rU   Úkeys       r)   rT   zPyJWKClient.match_kid×   s<   € ð ˆàð 	ð 	ˆCØŒz˜SÒ Ð Ø!�Ø�ð !ð Ðr+   )Fr   Tr   Nr   N)r   r   r   r   r   r   r   r   r   r   r   r   r    r   r!   r"   )r,   r   )F)r?   r   r,   r   )r?   r   r,   rF   )rR   r   r,   r
   )rV   rW   r,   r
   )rP   rF   rR   r   r,   r_   )Ú__name__Ú
__module__Ú__qualname__r*   r>   rE   rQ   r'   r^   ÚstaticmethodrT   © r+   r)   r   r      sØ   € € € € € ð !Ø!Ø"ØØ)-ØØ)-ðL3ð L3ð L3ð L3ð L3ð\0ð 0ð 0ð 0ð:(ð (ð (ð (ð (ð.ð ð ð ð ð2ð ð ð ð87ð 7ð 7ð 7ð ðð ð ñ „\ðð ð r+   r   )Ú
__future__r   r4   Úurllib.requestr0   Ú	functoolsr   Ússlr   Útypingr   Úurllib.errorr   r   Úapi_jwkr
   r   Úapi_jwtr   r\   Ú
exceptionsr   r   r&   r   r   rf   r+   r)   ú<module>rp      s
  ðØ "Ð "Ð "Ð "Ð "Ð "à €€€Ø Ð Ð Ð Ø Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð Ø ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,à $Ð $Ð $Ð $Ð $Ð $Ð $Ð $Ø 4Ð 4Ð 4Ð 4Ð 4Ð 4Ø DÐ DÐ DÐ DÐ DÐ DÐ DÐ DØ &Ð &Ð &Ð &Ð &Ð &ðYð Yð Yð Yð Yñ Yô Yð Yð Yð Yr+   