codekingpro/portable-devtools
114k
1"""2 authlib.rfc6750.errors3 ~~~~~~~~~~~~~~~~~~~~~~4 5 OAuth Extensions Error Registration. When a request fails,6 the resource server responds using the appropriate HTTP7 status code and includes one of the following error codes8 in the response.9 10 https://tools.ietf.org/html/rfc6750#section-6.211 12 :copyright: (c) 2017 by Hsiaoming Yang.13"""14from ..base import OAuth2Error15 16__all__ = [17 'InvalidTokenError', 'InsufficientScopeError'18]19 20 21class InvalidTokenError(OAuth2Error):22 """The access token provided is expired, revoked, malformed, or23 invalid for other reasons. The resource SHOULD respond with24 the HTTP 401 (Unauthorized) status code. The client MAY25 request a new access token and retry the protected resource26 request.27 28 https://tools.ietf.org/html/rfc6750#section-3.129 """30 error = 'invalid_token'31 description = (32 'The access token provided is expired, revoked, malformed, '33 'or invalid for other reasons.'34 )35 status_code = 40136 37 def __init__(self, description=None, uri=None, status_code=None,38 state=None, realm=None, **extra_attributes):39 super().__init__(40 description, uri, status_code, state)41 self.realm = realm42 self.extra_attributes = extra_attributes43 44 def get_headers(self):45 """If the protected resource request does not include authentication46 credentials or does not contain an access token that enables access47 to the protected resource, the resource server MUST include the HTTP48 "WWW-Authenticate" response header field; it MAY include it in49 response to other conditions as well.50 51 https://tools.ietf.org/html/rfc6750#section-352 """53 headers = super().get_headers()54 55 extras = []56 if self.realm:57 extras.append(f'realm="{self.realm}"')58 if self.extra_attributes:59 extras.extend([f'{k}="{self.extra_attributes[k]}"' for k in self.extra_attributes])60 extras.append(f'error="{self.error}"')61 error_description = self.get_error_description()62 extras.append(f'error_description="{error_description}"')63 headers.append(64 ('WWW-Authenticate', 'Bearer ' + ', '.join(extras))65 )66 return headers67 68 69class InsufficientScopeError(OAuth2Error):70 """The request requires higher privileges than provided by the71 access token. The resource server SHOULD respond with the HTTP72 403 (Forbidden) status code and MAY include the "scope"73 attribute with the scope necessary to access the protected74 resource.75 76 https://tools.ietf.org/html/rfc6750#section-3.177 """78 error = 'insufficient_scope'79 description = 'The request requires higher privileges than provided by the access token.'80 status_code = 40381 