codekingpro/portable-devtools
114k
1"""2 authlib.oauth2.rfc6749.models3 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~4 5 This module defines how to construct Client, AuthorizationCode and Token.6"""7from authlib.deprecate import deprecate8 9 10class ClientMixin:11 """Implementation of OAuth 2 Client described in `Section 2`_ with12 some methods to help validation. A client has at least these information:13 14 * client_id: A string represents client identifier.15 * client_secret: A string represents client password.16 * token_endpoint_auth_method: A way to authenticate client at token17 endpoint.18 19 .. _`Section 2`: https://tools.ietf.org/html/rfc6749#section-220 """21 22 def get_client_id(self):23 """A method to return client_id of the client. For instance, the value24 in database is saved in a column called ``client_id``::25 26 def get_client_id(self):27 return self.client_id28 29 :return: string30 """31 raise NotImplementedError()32 33 def get_default_redirect_uri(self):34 """A method to get client default redirect_uri. For instance, the35 database table for client has a column called ``default_redirect_uri``::36 37 def get_default_redirect_uri(self):38 return self.default_redirect_uri39 40 :return: A URL string41 """42 raise NotImplementedError()43 44 def get_allowed_scope(self, scope):45 """A method to return a list of requested scopes which are supported by46 this client. For instance, there is a ``scope`` column::47 48 def get_allowed_scope(self, scope):49 if not scope:50 return ''51 allowed = set(scope_to_list(self.scope))52 return list_to_scope([s for s in scope.split() if s in allowed])53 54 :param scope: the requested scope.55 :return: string of scope56 """57 raise NotImplementedError()58 59 def check_redirect_uri(self, redirect_uri):60 """Validate redirect_uri parameter in Authorization Endpoints. For61 instance, in the client table, there is an ``allowed_redirect_uris``62 column::63 64 def check_redirect_uri(self, redirect_uri):65 return redirect_uri in self.allowed_redirect_uris66 67 :param redirect_uri: A URL string for redirecting.68 :return: bool69 """70 raise NotImplementedError()71 72 def check_client_secret(self, client_secret):73 """Check client_secret matching with the client. For instance, in74 the client table, the column is called ``client_secret``::75 76 import secrets77 78 def check_client_secret(self, client_secret):79 return secrets.compare_digest(self.client_secret, client_secret)80 81 :param client_secret: A string of client secret82 :return: bool83 """84 raise NotImplementedError()85 86 def check_endpoint_auth_method(self, method, endpoint):87 """Check if client support the given method for the given endpoint.88 There is a ``token_endpoint_auth_method`` defined via `RFC7591`_.89 Developers MAY re-implement this method with::90 91 def check_endpoint_auth_method(self, method, endpoint):92 if endpoint == 'token':93 # if client table has ``token_endpoint_auth_method``94 return self.token_endpoint_auth_method == method95 return True96 97 Method values defined by this specification are:98 99 * "none": The client is a public client as defined in OAuth 2.0,100 and does not have a client secret.101 102 * "client_secret_post": The client uses the HTTP POST parameters103 as defined in OAuth 2.0104 105 * "client_secret_basic": The client uses HTTP Basic as defined in106 OAuth 2.0107 108 .. _`RFC7591`: https://tools.ietf.org/html/rfc7591109 """110 raise NotImplementedError()111 112 def check_token_endpoint_auth_method(self, method):113 deprecate('Please implement ``check_endpoint_auth_method`` instead.')114 return self.check_endpoint_auth_method(method, 'token')115 116 def check_response_type(self, response_type):117 """Validate if the client can handle the given response_type. There118 are two response types defined by RFC6749: code and token. For119 instance, there is a ``allowed_response_types`` column in your client::120 121 def check_response_type(self, response_type):122 return response_type in self.response_types123 124 :param response_type: the requested response_type string.125 :return: bool126 """127 raise NotImplementedError()128 129 def check_grant_type(self, grant_type):130 """Validate if the client can handle the given grant_type. There are131 four grant types defined by RFC6749:132 133 * authorization_code134 * implicit135 * client_credentials136 * password137 138 For instance, there is a ``allowed_grant_types`` column in your client::139 140 def check_grant_type(self, grant_type):141 return grant_type in self.grant_types142 143 :param grant_type: the requested grant_type string.144 :return: bool145 """146 raise NotImplementedError()147 148 149class AuthorizationCodeMixin:150 def get_redirect_uri(self):151 """A method to get authorization code's ``redirect_uri``.152 For instance, the database table for authorization code has a153 column called ``redirect_uri``::154 155 def get_redirect_uri(self):156 return self.redirect_uri157 158 :return: A URL string159 """160 raise NotImplementedError()161 162 def get_scope(self):163 """A method to get scope of the authorization code. For instance,164 the column is called ``scope``::165 166 def get_scope(self):167 return self.scope168 169 :return: scope string170 """171 raise NotImplementedError()172 173 174class TokenMixin:175 def check_client(self, client):176 """A method to check if this token is issued to the given client.177 For instance, ``client_id`` is saved on token table::178 179 def check_client(self, client):180 return self.client_id == client.client_id181 182 :return: bool183 """184 raise NotImplementedError()185 186 def get_scope(self):187 """A method to get scope of the authorization code. For instance,188 the column is called ``scope``::189 190 def get_scope(self):191 return self.scope192 193 :return: scope string194 """195 raise NotImplementedError()196 197 def get_expires_in(self):198 """A method to get the ``expires_in`` value of the token. e.g.199 the column is called ``expires_in``::200 201 def get_expires_in(self):202 return self.expires_in203 204 :return: timestamp int205 """206 raise NotImplementedError()207 208 def is_expired(self):209 """A method to define if this token is expired. For instance,210 there is a column ``expired_at`` in the table::211 212 def is_expired(self):213 return self.expired_at < now214 215 :return: boolean216 """217 raise NotImplementedError()218 219 def is_revoked(self):220 """A method to define if this token is revoked. For instance,221 there is a boolean column ``revoked`` in the table::222 223 def is_revoked(self):224 return self.revoked225 226 :return: boolean227 """228 raise NotImplementedError()229 