3
ãde½  ã               @   s~   d dl Z d dlZd dlZd dlZd dlZejeƒZdd„ ZG dd„ de	ƒZ
G dd„ de	ƒZG dd	„ d	e
ƒZe
ZeZeje_dS )
é    Nc          	   C   s   y| j dd�S    | S d S )Nzutf-8)Úencoding)Úencode)Úraw© r   úO/var/www/agendate/envp3/lib/python3.6/site-packages/msal/oauth2cli/assertion.pyÚ
_str2bytes   s    r   c               @   s    e Zd Zddd„Zddd„ZdS )	ÚAssertionCreatorNéX  c       	      K   s   t dƒ‚dS )a+  Create an assertion in bytes, based on the provided claims.

        All parameter names are defined in https://tools.ietf.org/html/rfc7521#section-5
        except the expires_in is defined here as lifetime-in-seconds,
        which will be automatically translated into expires_at in UTC.
        z Will be implemented by sub-classN)ÚNotImplementedError)	ÚselfÚaudienceÚissuerÚsubjectÚ
expires_atÚ
expires_inÚ	issued_atÚassertion_idÚkwargsr   r   r   Úcreate_normal_assertion   s    	z(AssertionCreator.create_normal_assertionc                s*   t |||||f‡ fdd„	t|d dƒd�S )zµCreate an assertion as a callable,
        which will then compute the assertion later when necessary.

        This is a useful optimization to reuse the client assertion.
        c                s   ˆ j | ||fd|i|—ŽS )Nr   )r   )ÚaÚiÚsÚer   )r   r   r   Ú<lambda>'   s    z@AssertionCreator.create_regenerative_assertion.<locals>.<lambda>é<   r   )r   )ÚAutoRefresherÚmax)r   r   r   r   r   r   r   )r   r   Úcreate_regenerative_assertion   s    z.AssertionCreator.create_regenerative_assertion)Nr	   NN)Nr	   )Ú__name__Ú
__module__Ú__qualname__r   r   r   r   r   r   r      s    

r   c               @   s"   e Zd ZdZddd„Zdd„ ZdS )	r   a  Cache the output of a factory, and auto-refresh it when necessary. Usage::

        r = AutoRefresher(time.time, expires_in=5)
        for i in range(15):
            print(r())  # the timestamp change only after every 5 seconds
            time.sleep(1)
    é  c             C   s   || _ || _i | _d S )N)Ú_factoryÚ_expires_inÚ_buf)r   Úfactoryr   r   r   r   Ú__init__4   s    zAutoRefresher.__init__c             C   s\   d\}}t j ƒ }| jj|dƒ|krFtjdƒ || jƒ ||| j i| _n
tjdƒ | jj|ƒS )Nr   Úvaluer   zRegenerating new assertionzReusing still valid assertion)r   r'   )Útimer$   ÚgetÚloggerÚdebugr"   r#   )r   Z
EXPIRES_ATZVALUEÚnowr   r   r   Ú__call__8   s    

zAutoRefresher.__call__N)r!   )r   r   r    Ú__doc__r&   r-   r   r   r   r   r   ,   s   
r   c               @   s    e Zd Zddd„Zddd„ZdS )	ÚJwtAssertionCreatorNc             C   s8   || _ || _|pi | _|r4tjtj|ƒƒjƒ | jd< dS )aÚ  Construct a Jwt assertion creator.

        Args:

            key (str):
                An unencrypted private key for signing, in a base64 encoded string.
                It can also be a cryptography ``PrivateKey`` object,
                which is how you can work with a previously-encrypted key.
                See also https://github.com/jpadilla/pyjwt/pull/525
            algorithm (str):
                "RS256", etc.. See https://pyjwt.readthedocs.io/en/latest/algorithms.html
                RSA and ECDSA algorithms require "pip install cryptography".
            sha1_thumbprint (str): The x5t aka X.509 certificate SHA-1 thumbprint.
            headers (dict): Additional headers, e.g. "kid" or "x5c" etc.
        Zx5tN)ÚkeyÚ	algorithmÚheadersÚbase64Úurlsafe_b64encodeÚbinasciiÚa2b_hexÚdecode)r   r0   r1   Zsha1_thumbprintr2   r   r   r   r&   D   s    
zJwtAssertionCreator.__init__éX  c
             K   s®   ddl }tjƒ }|||p||p$|| |p*||p8ttjƒ ƒdœ}|rJ||d< |j|	pTi ƒ y |j|| j| j| j	d�}t
|ƒS    | jjdƒs˜| jjdƒr¢tjdƒ ‚ Y nX dS )	zÀCreate a JWT Assertion.

        Parameters are defined in https://tools.ietf.org/html/rfc7523#section-3
        Key-value pairs in additional_claims will be added into payload as-is.
        r   N)ZaudZissÚsubÚexpZiatZjtiZnbf)r1   r2   ZRSÚESz•Some algorithms requires "pip install cryptography". See https://pyjwt.readthedocs.io/en/latest/installation.html#cryptographic-dependencies-optional)Újwtr(   ÚstrÚuuidÚuuid4Úupdater   r0   r1   r2   r   Ú
startswithr*   Ú	exception)r   r   r   r   r   r   r   r   Z
not_beforeZadditional_claimsr   r<   r,   ÚpayloadZstr_or_bytesr   r   r   r   [   s(    	
z+JwtAssertionCreator.create_normal_assertion)NN)NNr8   NNNN)r   r   r    r&   r   r   r   r   r   r/   C   s   
  r/   )r(   r5   r3   r>   ÚloggingÚ	getLoggerr   r*   r   Úobjectr   r   r/   ZSignerZ	JwtSignerr   Zsign_assertionr   r   r   r   Ú<module>   s   
;