codekingpro/portable-devtools
114k
1from authlib.common.urls import add_params_to_qs2from .assertion import client_secret_jwt_sign, private_key_jwt_sign3from .client import ASSERTION_TYPE4 5 6class ClientSecretJWT:7 """Authentication method for OAuth 2.0 Client. This authentication8 method is called ``client_secret_jwt``, which is using ``client_id``9 and ``client_secret`` constructed with JWT to identify a client.10 11 Here is an example of use ``client_secret_jwt`` with Requests Session::12 13 from authlib.integrations.requests_client import OAuth2Session14 15 token_endpoint = 'https://example.com/oauth/token'16 session = OAuth2Session(17 'your-client-id', 'your-client-secret',18 token_endpoint_auth_method='client_secret_jwt'19 )20 session.register_client_auth_method(ClientSecretJWT(token_endpoint))21 session.fetch_token(token_endpoint)22 23 :param token_endpoint: A string URL of the token endpoint24 :param claims: Extra JWT claims25 :param headers: Extra JWT headers26 :param alg: ``alg`` value, default is HS25627 """28 name = 'client_secret_jwt'29 alg = 'HS256'30 31 def __init__(self, token_endpoint=None, claims=None, headers=None, alg=None):32 self.token_endpoint = token_endpoint33 self.claims = claims34 self.headers = headers35 if alg is not None:36 self.alg = alg37 38 def sign(self, auth, token_endpoint):39 return client_secret_jwt_sign(40 auth.client_secret,41 client_id=auth.client_id,42 token_endpoint=token_endpoint,43 claims=self.claims,44 header=self.headers,45 alg=self.alg,46 )47 48 def __call__(self, auth, method, uri, headers, body):49 token_endpoint = self.token_endpoint50 if not token_endpoint:51 token_endpoint = uri52 53 client_assertion = self.sign(auth, token_endpoint)54 body = add_params_to_qs(body or '', [55 ('client_assertion_type', ASSERTION_TYPE),56 ('client_assertion', client_assertion)57 ])58 return uri, headers, body59 60 61class PrivateKeyJWT(ClientSecretJWT):62 """Authentication method for OAuth 2.0 Client. This authentication63 method is called ``private_key_jwt``, which is using ``client_id``64 and ``private_key`` constructed with JWT to identify a client.65 66 Here is an example of use ``private_key_jwt`` with Requests Session::67 68 from authlib.integrations.requests_client import OAuth2Session69 70 token_endpoint = 'https://example.com/oauth/token'71 session = OAuth2Session(72 'your-client-id', 'your-client-private-key',73 token_endpoint_auth_method='private_key_jwt'74 )75 session.register_client_auth_method(PrivateKeyJWT(token_endpoint))76 session.fetch_token(token_endpoint)77 78 :param token_endpoint: A string URL of the token endpoint79 :param claims: Extra JWT claims80 :param headers: Extra JWT headers81 :param alg: ``alg`` value, default is RS25682 """83 name = 'private_key_jwt'84 alg = 'RS256'85 86 def sign(self, auth, token_endpoint):87 return private_key_jwt_sign(88 auth.client_secret,89 client_id=auth.client_id,90 token_endpoint=token_endpoint,91 claims=self.claims,92 header=self.headers,93 alg=self.alg,94 )95 