codekingpro/portable-devtools
114k
1from ..rfc6749 import UnsupportedTokenTypeError2from ..rfc7009 import RevocationEndpoint3from authlib.common.errors import ContinueIteration4from authlib.oauth2.rfc6750.errors import InvalidTokenError5from authlib.oauth2.rfc9068.token_validator import JWTBearerTokenValidator6 7 8class JWTRevocationEndpoint(RevocationEndpoint):9 '''JWTRevocationEndpoint inherits from `RFC7009`_10 :class:`~authlib.oauth2.rfc7009.RevocationEndpoint`.11 12 The JWT access tokens cannot be revoked.13 If the submitted token is a JWT access token, then revocation returns14 a `invalid_token_error`.15 16 :param issuer: The issuer identifier.17 18 :param \\*\\*kwargs: Other parameters are inherited from19 :class:`~authlib.oauth2.rfc7009.RevocationEndpoint`.20 21 Plain text access tokens and other kind of tokens such as refresh_tokens22 will be ignored by this endpoint and passed to the next revocation endpoint::23 24 class MyJWTAccessTokenRevocationEndpoint(JWTRevocationEndpoint):25 def get_jwks(self):26 ...27 28 authorization_server.register_endpoint(29 MyJWTAccessTokenRevocationEndpoint(30 issuer="https://authorization-server.example.org",31 )32 )33 authorization_server.register_endpoint(MyRefreshTokenRevocationEndpoint)34 35 .. _RFC7009: https://tools.ietf.org/html/rfc700936 '''37 38 def __init__(self, issuer, server=None, *args, **kwargs):39 super().__init__(*args, server=server, **kwargs)40 self.issuer = issuer41 42 def authenticate_token(self, request, client):43 ''''''44 self.check_params(request, client)45 46 # do not attempt to revoke refresh_tokens47 if request.form.get('token_type_hint') not in ('access_token', None):48 raise ContinueIteration()49 50 validator = JWTBearerTokenValidator(issuer=self.issuer, resource_server=None)51 validator.get_jwks = self.get_jwks52 53 try:54 validator.authenticate_token(request.form['token'])55 56 # if the token is not a JWT, fall back to the regular flow57 except InvalidTokenError:58 raise ContinueIteration()59 60 # JWT access token cannot be revoked61 raise UnsupportedTokenTypeError()62 63 def get_jwks(self):64 '''Return the JWKs that will be used to check the JWT access token signature.65 Developers MUST re-implement this method::66 67 def get_jwks(self):68 return load_jwks("jwks.json")69 '''70 raise NotImplementedError()71 