Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes15kdownloads
auth.cpython-313.pyc696 linesDownload Raw Back to __pycache__
1�

2��j����SrSSKrSSKrSSKrSSKrSSKrSSKrSSKrSSK	r	SSK3Jr SSK4Jr SSK
Jr SSKJr SSKJr SSKJrJrJrJrJrJrJr "S	S5\5r"SS5r"S
S5r"SS5r"SS\5r "SS\5r!"SS\5r"0S4S\\#\4S\#S\#S\\#\4S\\\#\4S\$4Sjjr%0S4S\\#\4S\#S\#S\\#\4S\\\#\4S\$4Sjjr&S\\#\$4S\#4S jr'S!\$S\\#\44S"jr(g)#a�	This module contains implementations of various third-party6authentication schemes.7 8All the classes in this file are class mixins designed to be used with9the `tornado.web.RequestHandler` class.  They are used in two ways:10 11* On a login handler, use methods such as ``authenticate_redirect()``,12  ``authorize_redirect()``, and ``get_authenticated_user()`` to13  establish the user's identity and store authentication tokens to your14  database and/or cookies.15* In non-login handlers, use methods such as ``facebook_request()``16  or ``twitter_request()`` to use the authentication tokens to make17  requests to the respective services.18 19They all take slightly different arguments due to the fact all these20services implement authentication and authorization slightly differently.21See the individual service classes below for complete documentation.22 23Example usage for Google OAuth:24 25.. testsetup::26 27    import urllib28 29.. testcode::30 31    class GoogleOAuth2LoginHandler(tornado.web.RequestHandler,32                                    tornado.auth.GoogleOAuth2Mixin):33        async def get(self):34            # Google requires an exact match for redirect_uri, so it's35            # best to get it from your app configuration instead of from36            # self.request.full_uri().37            redirect_uri = urllib.parse.urljoin(self.application.settings['redirect_base_uri'],38                self.reverse_url('google_oauth'))39            async def get(self):40                if self.get_argument('code', False):41                    access = await self.get_authenticated_user(42                        redirect_uri=redirect_uri,43                        code=self.get_argument('code'))44                    user = await self.oauth2_request(45                        "https://www.googleapis.com/oauth2/v1/userinfo",46                        access_token=access["access_token"])47                    # Save the user and access token. For example:48                    user_cookie = dict(id=user["id"], access_token=access["access_token"])49                    self.set_signed_cookie("user", json.dumps(user_cookie))50                    self.redirect("/")51                else:52                    self.authorize_redirect(53                        redirect_uri=redirect_uri,54                        client_id=self.get_google_oauth_settings()['key'],55                        scope=['profile', 'email'],56                        response_type='code',57                        extra_params={'approval_prompt': 'auto'})58 59�N)�60httpclient)�escape)�61url_concat)�unicode_type)�RequestHandler)�List�Any�Dict�cast�Iterable�Union�Optionalc��\rSrSrSrg)�	AuthError�Z�N)�__name__�62__module__�__qualname__�__firstlineno__�__static_attributes__r��RD:\code\apps\devtools\python\user_packages\Python313\site-packages\tornado/auth.pyrrZs��rrc��\rSrSrSrS/SQ4S\\S\\SS4SjjrSS	\\	RS\\\44S63jjr
/S4S\S\\S\\S\\\44SjjrS
\	R S\\\44SjrS\	R4SjrSrg)�OpenIdMixin�^z�Abstract implementation of OpenID and Attribute Exchange.64 65Class attributes:66 67* ``_OPENID_ENDPOINT``: the identity provider's URI.68N)�name�email�language�username�callback_uri�ax_attrs�returnc�69�[[U5nU=(d URRnUceUR	XS9nUR70nUR
US-[RRU5-5 g)aHRedirects to the authentication URL for this service.71 72After authentication, the service will redirect back to the given73callback URI with additional parameters including ``openid.mode``.74 75We request the given attributes for the authenticated user by76default (name, email, language, and username). If you don't need77all those attributes for your app, you can request fewer with78the ax_attrs keyword argument.79 80.. versionchanged:: 6.081 82    The ``callback`` argument was removed and this method no83    longer returns an awaitable object. It is now an ordinary84    synchronous function.85N)r"�?)86rr�request�uri�_openid_args�_OPENID_ENDPOINT�redirect�urllib�parse�	urlencode)�selfr!r"�handler�args�endpoints      r�authenticate_redirect�!OpenIdMixin.authenticate_redirectfst��*�~�t�,��#�:�w���':�':���'�'�'�� � �� �A���(�(������C��&�,�,�*@�*@��*F�F�Gr�http_clientc��# �[[U5nURRR	5VVs0sH87up4X4S_M nnnSUS'UR88nUcUR
5nURUS[RRU5S9IShv�NnURU5$s snnfN7f)aFetches the authenticated user data upon redirect.89 90This method should be called by the handler that receives the91redirect from the `authenticate_redirect()` method (which is92often the same as the one that calls it; in that case you would93call `get_authenticated_user` if the ``openid.mode`` parameter94is present and `authenticate_redirect` if it is not).95 96The result of this method will generally be used to set a cookie.97 98.. versionchanged:: 6.099 100    The ``callback`` argument was removed. Use the returned101    awaitable object instead.102������check_authentication�openid.modeN�POST��method�body)rrr&�	arguments�itemsr)�get_auth_http_client�fetchr+r,r-�_on_authentication_verified)r.r4r/�k�vr0�url�resps        r�get_authenticated_user�"OpenIdMixin.get_authenticated_user�s����$�~�t�,��")���!:�!:�!@�!@�!B�103�!B���A��u�H�!B�	
�104�5��]���#�#�����3�3�5�K� �&�&���V�\�\�%;�%;�D�%A�'�105�106���/�/��5�5��107�108�s�8C�B9�AC�#B?�$C�oauth_scopec��[[U5n[RR	UR109R
5U5nSSSU[RR	US5SS.nU(a�URSSS.5 [U5n/nS	U;a#U1S110k-nU/SQ-
nURSS
SS.5 SSSS.nUHn	X�USU	-'URU	5 M  SRU5US'U(a;URSUR111RRS5SUS.5 U$)Nz http://specs.openid.net/auth/2.0z2http://specs.openid.net/auth/2.0/identifier_select�/�
checkid_setup)z	openid.ns�openid.claimed_idzopenid.identityzopenid.return_tozopenid.realmr8�http://openid.net/srv/ax/1.0�
fetch_request)zopenid.ns.axzopenid.ax.moder>r�fullname�lastname�	firstname)rQrOrP�$http://axschema.org/namePerson/first�http://axschema.org/namePerson�#http://axschema.org/namePerson/last)zopenid.ax.type.firstnamezopenid.ax.type.fullnamezopenid.ax.type.lastname�!http://axschema.org/contact/email�!http://axschema.org/pref/language�'http://axschema.org/namePerson/friendly)rrr zopenid.ax.type.�,zopenid.ax.requiredz,http://specs.openid.net/extensions/oauth/1.0�:r)zopenid.ns.oauthzopenid.oauth.consumerzopenid.oauth.scope)
rrr+r,�urljoinr&�full_url�update�set�append�join�host�split)112r.r!r"rHr/rDr0�required�known_attrsrs113          rr(�OpenIdMixin._openid_args�sR���~�t�,���l�l�"�"�7�?�?�#;�#;�#=�|�L��;�!U�S� #�"�L�L�0�0��c�:�*�
114����K�K�$B�&5��
��8�}�H��H���!��I�I���A�A�����4Z�3S�3X���=�?�E��K�115!��1<�1B��&��-�.�����%�!�*-���(�);�D�%�&���K�K�'U�-4�_�_�-A�-A�-G�-G��-L�Q�-O�*5��
��r�responsec�V^
^�[[U5mSUR;a[SUR-5eSm
TRR116H7nUR
S5(dMTRU5S:XdM2USSm
 O S[S[4U
U4SjjnU"S	5nU"S1175nU"S5nU"S5nU"S
5nU"S5R5n	[5n118/nU(aXjS'URU5 U(aXzS'URU5 U(aXZS'O:U(aSRU5U119S'OU(aURS5SU120S'U(aXJS'U	(aX�S'U(aX�S'TRSS5nU(aX�S'U121$)Ns
is_valid:truezInvalid OpenID response: %rz122openid.ns.rM�123r'r#c�B>�T(dgST-S-nSnTRRR5HKnTRU5U:XdMUR	U5(dM2U[U5SnST-S-U-n O U(dgTRUS5$)N�zopenid.z.type.z.value.)r&r=�keys�get_argument�124startswith�len)r'�prefix�ax_namer�part�ax_nsr/s     ��r�125get_ax_arg�;OpenIdMixin._on_authentication_verified.<locals>.get_ax_arg�s��������&��1�F��G����1�1�6�6�8���'�'��-��4�����9P�9P���F��
�.�D�'�%�/�)�;�d�B�G��	9�126���'�'���4�4rrUrSrRrTrWrV�127first_name�	last_namer� �@rr�localer rL�128claimed_id)rrr<rr&r=rlrk�str�lower�dictr^r_ra)r.re�keyrrrrrtrur rx�user�129name_partsryrqr/s             @@rrA�'OpenIdMixin._on_authentication_verified�s�����~�t�,���8�=�=�0��9�H�M�M�I�J�J����?�?�,�,�C����|�,�,��(�(��-�1O�O��B�C����
-�	5�C�	5�C�	5�	5��>�?���:�;��� F�G�130��D�E�	��G�H���?�@�F�F�H���v���131��!+������j�)�� )������i�(����L�
��8�8�J�/�D��L�
� �;�;�s�+�A�.�D��L��!��M��#��N��'����)�)�*=�t�D�132��!+����rc�,�[R"5$�z�Returns the `.AsyncHTTPClient` instance to be used for auth requests.133 134May be overridden by subclasses to use an HTTP client other than135the default.136�r�AsyncHTTPClient�r.s rr?� OpenIdMixin.get_auth_http_client����)�)�+�+rr�N)rrrr�__doc__rrzrr2rr�r137r	rFrr(�HTTPResponserAr?rrrrrr^s����'+�G�H��s�m�H��s�)�H�138�	H�:CG�6�#�J�$>�$>�?�6�	
�c�3�h��6�F#%�%)�	4��4��3�-�4��c�]�	4�139140�c�3�h��4�l<�"�/�/�<�	
�c�3�h��<�|,�j�&@�&@�,rrc
���\rSrSrSrSS\\S\\\\4S\\	RSS4SjjrSS\\	RS\\\44S	jjrSS\\S\\\\4S\4S141jjr
S\S\\S\	RSS4S
jrS\\\4S\4SjrS\\\44SjrS\\\4S\\\44Sjr0S4S\S\\\4S\\\4S\S\\\44142SjjrS\	R4SjrSrg)�143OAuthMixiniaAbstract implementation of OAuth 1.0 and 1.0a.144 145See `TwitterMixin` below for an example implementation.146 147Class attributes:148 149* ``_OAUTH_AUTHORIZE_URL``: The service's OAuth authorization url.150* ``_OAUTH_ACCESS_TOKEN_URL``: The service's OAuth access token url.151* ``_OAUTH_VERSION``: May be either "1.0" or "1.0a".152* ``_OAUTH_NO_CALLBACKS``: Set this to True if the service requires153  advance registration of callbacks.154 155Subclasses must also override the `_oauth_get_user_future` and156`_oauth_consumer_token` methods.157Nr!�extra_paramsr4r#c��# �U(a[USS5(a[S5eUcUR5nUce[USS5S:Xa'URUR	XS95IShv�NnO'URUR	55IShv�NnUR158nUR
XQU5 gNKN%7f)a�Redirects the user to obtain OAuth authorization for this service.159 160The ``callback_uri`` may be omitted if you have previously161registered a callback URI with the third-party service. For162some services, you must use a previously-registered callback163URI and cannot specify a callback via this method.164 165This method sets a cookie called ``_oauth_request_token`` which is166subsequently used (and cleared) in `get_authenticated_user` for167security purposes.168 169This method is asynchronous and must be called with ``await``170or ``yield`` (This is different from other ``auth*_redirect``171methods defined in this module). It calls172`.RequestHandler.finish` for you so you should not write any173other response after it returns.174 175.. versionchanged:: 3.1176   Now returns a `.Future` and takes an optional callback, for177   compatibility with `.gen.coroutine`.178 179.. versionchanged:: 6.0180 181   The ``callback`` argument was removed. Use the returned182   awaitable object instead.183 184�_OAUTH_NO_CALLBACKSFz,This service does not support oauth_callbackN�_OAUTH_VERSION�1.0a)r!r�)�getattr�	Exceptionr?r@�_oauth_request_token_url�_OAUTH_AUTHORIZE_URL�_on_request_token)r.r!r�r4rerDs      r�authorize_redirect�OAuthMixin.authorize_redirect0s����B�G�D�*?��G�G��J�K�K����3�3�5�K��&�&�&��4�)�6�2�f�<�(�.�.��-�-�!-�.����H�)�.�.�t�/L�/L�/N�O�O�H��'�'�����s�(�;��P�s$�A/C�1B=�2'C�B?�$C�?Cc��# �[[U5n[R"UR	S55nUR	SS5nURS5nU(d[
S5eURS5 SURS55upgXc:wa[
S5e[XgS	9nU(aXHS185'UcUR5nUceURURU55IShv�Nn	[U	R5n186URU1875IShv�NnU(d[
S5eX�S'U$NJN7f)
a5Gets the OAuth authorized user and access token.188 189This method should be called from the handler for your190OAuth callback URL to complete the registration process. We run the191callback with the authenticated user dictionary.  This dictionary192will contain an ``access_key`` which can be used to make authorized193requests to this service on behalf of the user.  The dictionary will194also contain other fields such as ``name``, depending on the service195used.196 197.. versionchanged:: 6.0198 199   The ``callback`` argument was removed. Use the returned200   awaitable object instead.201�oauth_token�oauth_verifierN�_oauth_request_tokenz"Missing OAuth request token cookiec3�v# �UH/n[R"[R"U55v� M1 g7fr�)�base64�	b64decoder�utf8)�.0�is  r�	<genexpr>�4OAuthMixin.get_authenticated_user.<locals>.<genexpr>zs*���%202�6O��F���V�[�[��^�,�,�6O�s�79�|z#Request token does not match cookie�r}�secret�verifierzError getting user�access_token)rrrr�rk�203get_cookier�clear_cookierar|r?r@�_oauth_access_token_url�_oauth_parse_responser<�_oauth_get_user_future)r.r4r/�request_keyr��request_cookie�204cookie_key�
cookie_secret�tokenrer�r~s            rrF�!OAuthMixin.get_authenticated_useras=���$�~�t�,���k�k�'�"6�"6�}�"E�F�� �-�-�.>��E�� �+�+�,B�C����@�A�A����3�4�%205�6D�6J�6J�3�6O�%206�!�207��$��A�B�B���208��� .�*�����3�3�5�K��&�&�&�$�*�*�4�+G�+G��+N�O�O��,�X�]�]�;���0�0��>�>����0�1�1�+�^����
P�>�s$�C5E�7E�8-E�%E�&E�Ec���[[U5nUR5nURn[	[209R"US5S[[[R"555[210R"[R"[R"5R55SS9n[USS5S:XatUS:XaSUS'OBU(a;[ R"R%UR&R)5U5US'U(aUR+U5 [-US	XV5nO
[/US	XV5nXvS211'US-[ R"R1U5-$)Nr}�	HMAC-SHA1�1.0)�oauth_consumer_key�oauth_signature_method�oauth_timestamp�oauth_nonce�
oauth_versionr�r��oob�oauth_callback�GET�oauth_signaturer%)rr�_oauth_consumer_token�_OAUTH_REQUEST_TOKEN_URLr|r�
to_basestringrz�int�time�binascii�b2a_hex�uuid�uuid4�bytesr�r+r,rZr&r[r\�_oauth10a_signature�_oauth_signaturer-)r.r!r�r/�consumer_tokenrDr0�	signatures        rr��#OAuthMixin._oauth_request_token_url�s.��212�~�t�,���3�3�5���+�+���%�3�3�N�5�4I�J�#.���D�I�I�K� 0�1��,�,�X�-=�-=�d�j�j�l�>P�>P�-Q�R��213���4�)�6�2�f�<��u�$�).��%�&��)/���)=�)=��O�O�,�,�.��*��%�&�����L�)�+�N�E�3�M�I�(����J�I�"+�
���S�y�6�<�<�1�1�$�7�7�7r�
authorize_urlrec��[[U5n[UR5n[R214"[R"US55S-[R215"[R"US55-nURSU5 [USS9nUS:Xa5URUS-[RRU5-5 gU(a;[RRURR!5U5US'UR#US-[RRU5-5 g)	Nr}�|r�r�)r�r�r%r�)rrr�r<r��	b64encoderr��216set_cookier|�finishr+r,r-rZr&r[r*)r.r�r!rer/�
request_token�datar0s        rr��OAuthMixin._on_request_token�s���~�t�,��-�h�m�m�<�
����V�[�[��u�)=�>�?��
����v�{�{�=��+B�C�D�
E�	
�217	���1�4�8��
�e� 4�5���5� ��N�N�=�3�.����1G�1G��1M�M�N��
�%+�\�\�%9�%9����(�(�*�L�&�D�!�"�	�����,�v�|�|�/E�/E�d�/K�K�Lrr�c�P�UR5nURn[[R"US5[R"US5S[[
[R"555[R"[R"[R"5R55SS9nSU;aUSUS'[USS5S:Xa[US	X4U5nO[US	X4U5nXTS218'US-[ R"R%U5-$)Nr}r�r��r�r�r�r�r�r�r�r�r�r�r�r�r%)r��_OAUTH_ACCESS_TOKEN_URLr|rr�rzr�r�r�r�r�r�r�r�r�r�r+r,r-)r.r�r�rDr0r�s      rr��"OAuthMixin._oauth_access_token_url�s���3�3�5���*�*���%�3�3�N�5�4I�J��,�,�]�5�-A�B�#.���D�I�I�K� 0�1��,�,�X�-=�-=�d�j�j�l�>P�>P�-Q�R��
219����&�%2�:�%>�D�!�"��4�)�6�2�f�<�+���s�-��I�)���s�-��I�#,�
���S�y�6�<�<�1�1�$�7�7�7rc��[5e)z�Subclasses must override this to return their OAuth consumer keys.220 221The return value should be a `dict` with keys ``key`` and ``secret``.222��NotImplementedErrorr�s rr�� OAuthMixin._oauth_consumer_token�s
��223"�#�#rr�c��# �[5e7f)aSubclasses must override this to get basic information about the224user.225 226Should be a coroutine whose result is a dictionary227containing information about the user, which may have been228retrieved by using ``access_token`` to make a request to the229service.230 231The access token will be added to the returned dictionary to make232the result of `get_authenticated_user`.233 234.. versionchanged:: 5.1235 236   Subclasses may also define this method with ``async def``.237 238.. versionchanged:: 6.0239 240   A synchronous fallback to ``_oauth_get_user`` was removed.241r�)r.r�s  rr��!OAuthMixin._oauth_get_user_future�s���,"�#�#�s�
r�rD�242parametersr;c�D�UR5n[[R"US5[R"US5S[	[[R"555[R"[R"[R"5R55SS9n0nURU5 URU5 [USS5S:Xa[XTXU5nO
[XTXU5n[R"U5US'U$)z�Returns the OAuth parameters as a dict for the given request.243 244parameters should include all POST arguments and query string arguments245that will be sent with the request.246r}r�r�r�r�r�r�)r�r|rr�rzr�r�r�r�r�r�r�r\r�r�r�)	r.rDr�r�r;r��	base_argsr0r�s	         r�_oauth_request_parameters�$OAuthMixin._oauth_request_parameters�s����3�3�5���%�3�3�N�5�4I�J��,�,�\�%�-@�A�#.���D�I�I�K� 0�1��,�,�X�-=�-=�d�j�j�l�>P�>P�-Q�R��
247�	������I�����J���4�)�6�2�f�<�+���<��I�)���<��I�(.�';�';�I�'F�	�#�$��rc�,�[R"5$r�r�r�s rr?�OAuthMixin.get_auth_http_client"r�rr)NNNr��NN)rrrrr�rrzr248r	rr�r�rFr�r�r�r�r�r�r�r?rrrrr�r�s����$'+�15�<@�	/<��s�m�/<��t�C��H�~�.�/<��j�8�8�9�	/<�249250�/<�dCG�,�#�J�$>�$>�?�,�	
�c�3�h��,�`'+�15�8��s�m�8��t�C��H�~�.�8�251
�	8�>M��M��s�m�M��)�)�	M�252253�M�08�T�#�s�(�^�8��8�4$�t�C��H�~�$�$� ��c��N�$�	
�c�3�h��$�8&(��!�
�!��3��8�n�!���c��N�	!�254�!�255�c�3�h��
!�F,�j�&@�&@�,rr�c�2�\rSrSrSrSS\\S\\S\\S\\\\4S	\\	\S256\SS4Sjjr257SS\\S\\S\\S\\S\\\\4S\4S
jjrSS\S\\S\\\\4S\S\4258SjjrS\
R4SjrSrg)�OAuth2Mixini+aAbstract implementation of OAuth 2.0.259 260See `FacebookGraphMixin` or `GoogleOAuth2Mixin` below for example261implementations.262 263Class attributes:264 265* ``_OAUTH_AUTHORIZE_URL``: The service's authorization url.266* ``_OAUTH_ACCESS_TOKEN_URL``:  The service's access token url.267N�code�redirect_uri�	client_id�
client_secretr��scope�
response_typer#c�6�Ub"S[5 [[U5nSU0nUbXS'UbX(S'U(aURU5 U(aSR
U5US'URn	UR[X�55 g)ayRedirects the user to obtain OAuth authorization for this service.268 269Some providers require that you register a redirect URL with270your application instead of passing one via this method. You271should call this method to log the user in, and then call272``get_authenticated_user`` in the handler for your273redirect URL to complete the authorization process.274 275.. versionchanged:: 6.0276 277   The ``callback`` argument and returned awaitable were removed;278   this is now an ordinary synchronous function.279 280.. deprecated:: 6.4281   The ``client_secret`` argument (which has never had any effect)282   is deprecated and will be removed in Tornado 7.0.283Nz$client_secret argument is deprecatedr�r�r�rvr�)284�warnings�warn�DeprecationWarningrrr\r_r�r*r)285r.r�r�r�r�r�r�r/r0rDs286          rr��OAuth2Mixin.authorize_redirect7s���4�$��M�M�@�BT�U��~�t�,����/���#�#/�� �� � )�����K�K��%���H�H�U�O�D��M��'�'������C�.�/rc��URn0nUbXS'UbXGS'UbX'S'UbX7S'U(aURU5 [Xg5$)Nr�r�r�r�)r�r\r)r.r�r�r�r�r�rDr0s        rr��$OAuth2Mixin._oauth_request_token_url`se���*�*�����#�#/�� �����L�� � )����$�$1��!���K�K��%��#�$�$rrDr��	post_argsr0c��# �0nU(aX%S'URU5 U(a%US[RRU5--
nUR	5nUb7URUS[RRU5S9IShv�NnOURU5IShv�Nn[R"UR5$N>N&7f)a�Fetches the given URL auth an OAuth2 access token.287 288If the request is a POST, ``post_args`` should be provided. Query289string arguments should be given as keyword arguments.290 291Example usage:292 293..testcode::294 295    class MainHandler(tornado.web.RequestHandler,296                      tornado.auth.FacebookGraphMixin):297        @tornado.web.authenticated298        async def get(self):299            new_entry = await self.oauth2_request(300                "https://graph.facebook.com/me/feed",301                post_args={"message": "I am posting from my Tornado application!"},302                access_token=self.current_user["access_token"])303 304            if not new_entry:305                # Call failed; perhaps missing permission?306                self.authorize_redirect()307                return308            self.finish("Posted a message!")309 310.. versionadded:: 4.3311 312.. versionchanged::: 6.0313 314   The ``callback`` argument was removed. Use the returned awaitable object instead.315r�r%Nr9r:)	r\r+r,r-r?r@r�json_decoder<)r.rDr�r�r0�all_args�httpres        r�oauth2_request�OAuth2Mixin.oauth2_requestvs����J���'3�^�$��O�O�D�!���3����/�/��9�9�9�C��(�(�*��� �!�Z�Z��F����)?�)?�	�)J�(���H�"�Z�Z��_�,�H��!�!�(�-�-�0�0��-�s$�BC�C�C�+C�,%C�Cc�,�[R"5$)z�Returns the `.AsyncHTTPClient` instance to be used for auth requests.316 317May be overridden by subclasses to use an HTTP client other than318the default.319 320.. versionadded:: 4.3321r�r�s rr?� OAuth2Mixin.get_auth_http_client�s���)�)�+�+rr)NNNNNr�)NNNNNr�)rrrrr�rrzr322r	rr�r�r�rr�r?rrrrr�r�+sU��	�'+�#'�'+�15�%)�#�'0��s�m�'0��C�=�'0� ��}�	'0�323�t�C��H�~�.�'0���S�	�"�
'0��'0�324�'0�V'+�#'�'+�"�15�
%��s�m�%��C�=�%� ��}�	%�325�s�m�%��t�C��H�~�.�
%�326
�%�2'+�.2�	31�
�31��s�m�31��D��c��N�+�	31�327�31�328
�
31�j,�j�&@�&@�,rr�c���\rSrSrSrSrSrSrSrSr	Sr329SS330\\SS	4Sjjr
SS
\S\\\4S\\\\4S\S\4331SjjrS\\\44SjrS\\\4S\\\44SjrSrg	)�TwitterMixini�a�Twitter OAuth authentication.332 333To authenticate with Twitter, register your application with334Twitter at http://twitter.com/apps. Then copy your Consumer Key335and Consumer Secret to the application336`~tornado.web.Application.settings` ``twitter_consumer_key`` and337``twitter_consumer_secret``. Use this mixin on the handler for the338URL you registered as your application's callback URL.339 340When your application is set up, you can use this mixin like this341to authenticate the user with Twitter and get access to their stream:342 343.. testcode::344 345    class TwitterLoginHandler(tornado.web.RequestHandler,346                              tornado.auth.TwitterMixin):347        async def get(self):348            if self.get_argument("oauth_token", None):349                user = await self.get_authenticated_user()350                # Save the user using e.g. set_signed_cookie()351            else:352                await self.authorize_redirect()353 354The user object returned by `~OAuthMixin.get_authenticated_user`355includes the attributes ``username``, ``name``, ``access_token``,356and all of the custom Twitter user attributes described at357https://dev.twitter.com/docs/api/1.1/get/users/show358 359.. deprecated:: 6.3360   This class refers to version 1.1 of the Twitter API, which has been361   deprecated by Twitter. Since Twitter has begun to limit access to its362   API, this class will no longer be updated and will be removed in the363   future.364z+https://api.twitter.com/oauth/request_tokenz*https://api.twitter.com/oauth/access_tokenz'https://api.twitter.com/oauth/authorizez*https://api.twitter.com/oauth/authenticateFzhttps://api.twitter.com/1.1Nr!r#c��# �UR5nURURUS95IShv�NnURURSU5 gN"7f)a�Just like `~OAuthMixin.authorize_redirect`, but365auto-redirects if authorized.366 367This is generally the right interface to use if you are using368Twitter for single-sign on.369 370.. versionchanged:: 3.1371   Now returns a `.Future` and takes an optional callback, for372   compatibility with `.gen.coroutine`.373 374.. versionchanged:: 6.0375 376   The ``callback`` argument was removed. Use the returned377   awaitable object instead.378)r!N)r?r@r�r��_OAUTH_AUTHENTICATE_URL)r.r!r�res    rr2�"TwitterMixin.authenticate_redirect�sX��� �(�(�*������)�)�|�)�D�379�380��	
���t�;�;�T�8�L�381�s�2A�A�#A�pathr�r�r0c��# �URS5(dURS5(aUnOURU-S-nU(aU0nURU5 URU=(d 05 UbSOSnURXRXgS9nURU5 U(a%US[R382R
U5--
nUR5n	Ub7U	RUS[R383R
U5S	9IShv�Nn384OU	RU5IShv�Nn385[R"U386R5$N>N&7f)387avFetches the given API path, e.g., ``statuses/user_timeline/btaylor``388 389The path should not include the format or API version number.390(we automatically use JSON format and API version 1).391 392If the request is a POST, ``post_args`` should be provided. Query393string arguments should be given as keyword arguments.394 395All the Twitter methods are documented at http://dev.twitter.com/396 397Many methods require an OAuth access token which you can398obtain through `~OAuthMixin.authorize_redirect` and399`~OAuthMixin.get_authenticated_user`. The user returned through that400process includes an 'access_token' attribute that can be used401to make authenticated requests via this method. Example402usage:403 404.. testcode::405 406    class MainHandler(tornado.web.RequestHandler,407                      tornado.auth.TwitterMixin):408        @tornado.web.authenticated409        async def get(self):410            new_entry = await self.twitter_request(411                "/statuses/update",412                post_args={"status": "Testing Tornado Web Server"},413                access_token=self.current_user["access_token"])414            if not new_entry:415                # Call failed; perhaps missing permission?416                await self.authorize_redirect()417                return418            self.finish("Posted a message!")419 420.. versionchanged:: 6.0421 422   The ``callback`` argument was removed. Use the returned423   awaitable object instead.424zhttp:zhttps:z.jsonNr9r�)r;r%r:)rl�_TWITTER_BASE_URLr\r�r+r,r-r?r@rr�r<)r.rr�r�r0rDr�r;�oauthr�res           r�twitter_request�TwitterMixin.twitter_request�s-���Z�?�?�7�#�#�t���x�'@�'@��C��(�(�4�/�'�9�C���H��O�O�D�!��O�O�I�O��,�(�4�V�%�F��2�2��8�3��E�
�K�K�����3����/�/��5�5�5�C��(�(�*��� �!�Z�Z��F����)?�)?�	�)J�(���H�"�Z�Z��_�,�H��!�!�(�-�-�0�0��-�s$�DE�E�E�*E�+%E�Ec��[[U5nURSS5 URSS5 [URSURSS9$)N�twitter_consumer_keyz
Twitter OAuth�twitter_consumer_secretr�)rr�require_settingr|�settings�r.r/s  rr��"TwitterMixin._oauth_consumer_token?s[���~�t�,����� 6��H���� 9�?�K��� � �!7�8��#�#�$=�>�425�	426rc��`# �URSUS9IShv�NnU(aUSUS'U$N7f)Nz/account/verify_credentials)r��screen_namer )r)r.r�r~s   rr��#TwitterMixin._oauth_get_user_futureHsD����)�)�)��*�427�428���#�M�2�D�����429�s�.�,�.rr�)rrrrr�r�r�r�rr�r430rrzr2r431r	rr�r�rrrrrr�s���!�F M��J��D��J����5��M���
�M�QU�M�4/3�	F1��F1��3��8�n�F1��D��c��N�+�	F1�432�F1�433
�
F1�P434�t�C��H�~�435�� ��c��N��	
�c�3�h��rrc
��\rSrSrSrSrSrSrSrSr	S\436\\44S	jrSS\S\S
\
\S\
\S\437\\44438SjjrSrg439)�GoogleOAuth2MixiniSa�Google authentication using OAuth2.440 441In order to use, register your application with Google and copy the442relevant parameters to your application settings.443 444* Go to the Google Dev Console at http://console.developers.google.com445* Select a project, or create a new one.446* Depending on permissions required, you may need to set your app to447  "testing" mode and add your account as a test user, or go through448  a verfication process. You may also need to use the "Enable449  APIs and Services" command to enable specific services.450* In the sidebar on the left, select Credentials.451* Click CREATE CREDENTIALS and click OAuth client ID.452* Under Application type, select Web application.453* Name OAuth 2.0 client and click Create.454* Copy the "Client secret" and "Client ID" to the application settings as455  ``{"google_oauth": {"key": CLIENT_ID, "secret": CLIENT_SECRET}}``456* You must register the ``redirect_uri`` you plan to use with this class457  on the Credentials page.458 459.. versionadded:: 3.2460z,https://accounts.google.com/o/oauth2/v2/authz*https://www.googleapis.com/oauth2/v4/tokenz-https://www.googleapis.com/oauth2/v1/userinfoF�google_oauthr#c�T�[[U5nURUR$)aZReturn the Google OAuth 2.0 credentials that you created with461[Google Cloud462Platform](https://console.cloud.google.com/apis/credentials). The dict463format is::464 465    {466        "key": "your_client_id", "secret": "your_client_secret"467    }468 469If your credentials are stored differently (e.g. in a db) you can470override this method for custom provision.471)rrr�_OAUTH_SETTINGS_KEYrs  r�get_google_oauth_settings�+GoogleOAuth2Mixin.get_google_oauth_settingsqs'���~�t�,������ 8� 8�9�9rNr�r�r�r�c��P# �UbUc UR5nUcUSnUcUSnUR5n[RR	UUUUSS.5nURURSSS0US	9IShv�Nn[R"UR5$N$7f)472a�Handles the login for the Google user, returning an access token.473 474The result is a dictionary containing an ``access_token`` field475([among others](https://developers.google.com/identity/protocols/OAuth2WebServer#handlingtheresponse)).476Unlike other ``get_authenticated_user`` methods in this package,477this method does not return any additional information about the user.478The returned access token can be used with `OAuth2Mixin.oauth2_request`479to request additional information (perhaps from480``https://www.googleapis.com/oauth2/v2/userinfo``)481 482Example usage:483 484.. testsetup::485 486    import urllib487 488.. testcode::489 490    class GoogleOAuth2LoginHandler(tornado.web.RequestHandler,491                                   tornado.auth.GoogleOAuth2Mixin):492        async def get(self):493            # Google requires an exact match for redirect_uri, so it's494            # best to get it from your app configuration instead of from495            # self.request.full_uri().496            redirect_uri = urllib.parse.urljoin(self.application.settings['redirect_base_uri'],497                self.reverse_url('google_oauth'))498            async def get(self):499                if self.get_argument('code', False):500                    access = await self.get_authenticated_user(501                        redirect_uri=redirect_uri,502                        code=self.get_argument('code'))503                    user = await self.oauth2_request(504                        "https://www.googleapis.com/oauth2/v1/userinfo",505                        access_token=access["access_token"])506                    # Save the user and access token. For example:507                    user_cookie = dict(id=user["id"], access_token=access["access_token"])508                    self.set_signed_cookie("user", json.dumps(user_cookie))509                    self.redirect("/")510                else:511                    self.authorize_redirect(512                        redirect_uri=redirect_uri,513                        client_id=self.get_google_oauth_settings()['key'],514                        scope=['profile', 'email'],515                        response_type='code',516                        extra_params={'approval_prompt': 'auto'})517 518.. versionchanged:: 6.0519 520   The ``callback`` argument was removed. Use the returned awaitable object instead.521Nr}r��authorization_code)r�r�r�r��522grant_typer9zContent-Typez!application/x-www-form-urlencoded)r;�headersr<)523rr?r+r,r-r@r�rr�r<)	r.r�r�r�r�rr�r<res	         rrF�(GoogleOAuth2Mixin.get_authenticated_user�s����t��
� 5��5�5�7�H�� �$�U�O�	��$� (�� 2�
��(�(�*���|�|�%�%� ,��&�!.�2�
�524������(�(��#�%H�I��	$�525�526���!�!�(�-�-�0�0�
527�s�A=B&�?B$�%B&rr�)rrrrr�r�r��_OAUTH_USERINFO_URLr�rr528rzrrr	rFrrrrrrSs����.J��J��I����(��:�4��S��>�:�($(�'+�Q1��Q1��Q1��C�=�	Q1�529 ��}�Q1�530�c�3�h��
Q1�Q1rrc��\rSrSrSrSrSrSrSrSS\	S	\	S531\	S\	S\532\\	\4S
\533\\	\44Sjjr
SS\	S\534\	S\535\\	\4S\S
\4536SjjrSrg)�FacebookGraphMixini�z;Facebook authentication using the new Graph API and OAuth2.z.https://graph.facebook.com/oauth/access_token?z&https://www.facebook.com/dialog/oauth?Fzhttps://graph.facebook.comNr�r�r�r��extra_fieldsr#c537��# �UR5nUUUUS.n1SknU(aURU5 URUR"S
0UD65IShv�Nn	[R538"U	R5nURS5URS5S.n539U540SceURSU541S[R"URS5U542SRS5[RS	9R5S543RU5S9IShv�NnUcg0nUHn
URU
5X�'M URU544S[!U545RS55S.5 U$GN NZ7f)a�Handles the login for the Facebook user, returning a user object.546 547Example usage:548 549.. testcode::550 551    class FacebookGraphLoginHandler(tornado.web.RequestHandler,552                                    tornado.auth.FacebookGraphMixin):553      async def get(self):554        redirect_uri = urllib.parse.urljoin(555            self.application.settings['redirect_base_uri'],556            self.reverse_url('facebook_oauth'))557        if self.get_argument("code", False):558            user = await self.get_authenticated_user(559                redirect_uri=redirect_uri,560                client_id=self.settings["facebook_api_key"],561                client_secret=self.settings["facebook_secret"],562                code=self.get_argument("code"))563            # Save the user with e.g. set_signed_cookie564        else:565            self.authorize_redirect(566                redirect_uri=redirect_uri,567                client_id=self.settings["facebook_api_key"],568                extra_params={"scope": "user_posts"})569 570This method returns a dictionary which may contain the following fields:571 572* ``access_token``, a string which may be passed to `facebook_request`573* ``session_expires``, an integer encoded as a string representing574  the time until the access token expires in seconds. This field should575  be used like ``int(user['session_expires'])``; in a future version of576  Tornado it will change from a string to an integer.577* ``id``, ``name``, ``first_name``, ``last_name``, ``locale``, ``picture``,578  ``link``, plus any fields named in the ``extra_fields`` argument. These579  fields are copied from the Facebook graph API580  `user object <https://developers.facebook.com/docs/graph-api/reference/user>`_581 582.. versionchanged:: 4.5583   The ``session_expires`` field was updated to support changes made to the584   Facebook API in March 2017.585 586.. versionchanged:: 6.0587 588   The ``callback`` argument was removed. Use the returned awaitable object instead.589)r�r�r�r�>�id�linkrrx�picturerurtNr��590expires_in)r�r,z/mer�)r}�msg�	digestmodrX)rr��appsecret_proof�fields)r��session_expiresr)r?r\r@r�rr�r<�get�facebook_request�hmac�new�encode�hashlib�sha256�	hexdigestr_rz)r.r�r�r�r�r'r�r0r0re�sessionr~�fieldmap�fields              rrF�)FacebookGraphMixin.get_authenticated_user�s����j�(�(�*��(��"�*�	591��X����M�M�,�'�����)�)�1�D�1�592�593���!�!�(�-�-�0�� �H�H�^�4��(�(�<�0�594���~�&�2�2�2��*�*�� ��0� �H�H�!�(�(��0��N�+�2�2�6�:�!�.�.���i�k��8�8�F�#�+�	595�	596���<�����E�"�h�h�u�o�H�O��	��� '�� 7�#&�w�{�{�<�'@�#A�
�	597���M598�	599�s&�AE?�E:�CE?�"E=�#AE?�=E?rr�r�r0c��f# �URU-nUR"U4X#S.UD6IShv�N$N7f)a�Fetches the given relative API path, e.g., "/btaylor/picture"600 601If the request is a POST, ``post_args`` should be provided. Query602string arguments should be given as keyword arguments.603 604An introduction to the Facebook Graph API can be found at605http://developers.facebook.com/docs/api606 607Many methods require an OAuth access token which you can608obtain through `~OAuth2Mixin.authorize_redirect` and609`get_authenticated_user`. The user returned through that610process includes an ``access_token`` attribute that can be611used to make authenticated requests via this method.612 613Example usage:614 615.. testcode::616 617    class MainHandler(tornado.web.RequestHandler,618                      tornado.auth.FacebookGraphMixin):619        @tornado.web.authenticated620        async def get(self):621            new_entry = await self.facebook_request(622                "/me/feed",623                post_args={"message": "I am posting from my Tornado application!"},624                access_token=self.current_user["access_token"])625 626            if not new_entry:627                # Call failed; perhaps missing permission?628                self.authorize_redirect()629                return630            self.finish("Posted a message!")631 632The given path is relative to ``self._FACEBOOK_BASE_URL``,633by default "https://graph.facebook.com".634 635This method is a wrapper around `OAuth2Mixin.oauth2_request`;636the only difference is that this method takes a relative path,637while ``oauth2_request`` takes a complete url.638 639.. versionchanged:: 3.1640   Added the ability to override ``self._FACEBOOK_BASE_URL``.641 642.. versionchanged:: 6.0643 644   The ``callback`` argument was removed. Use the returned awaitable object instead.645)r�r�N)�_FACEBOOK_BASE_URLr�)r.rr�r�r0rDs      rr3�#FacebookGraphMixin.facebook_requestFsH���l�%�%��,���(�(��646�*�647�CG�648�649�	650�651�s�(1�/�1rr�r�)rrrrr�r�r�r�r?rzrr652r	rFr3rrrrr&r&�s���E�N��C����5��26�
g��g��g��	g�653�g��t�C��H�~�.�
g�654�$�s�C�x�.�	!�g�X'+�.2�	9655��9656��s�m�9657��D��c��N�+�	9658�659�9660�661
�
9662�9663rr&r�r;rDr�r�r#c	�(�[RRU5nUSSupgnUR5S-UR5-U-n	/n664U665R	UR55 U666R	U	5 U667R	SR
S[UR55555 SR
SU66855n[R"US5/nUR	[R"U(aUSOS55 S	R
U5n
[R"U
[R"U5[R5n[R "UR#55SS669$)zpCalculates the HMAC-SHA1 OAuth signature for the given request.670 671See http://oauth.net/core/1.0/#signing_process672N��://�&c3�X# �UH upUS[[U553v� M" g7f��=N��
_oauth_escaperz�r�rBrCs   rr��#_oauth_signature.<locals>.<genexpr>��)���W�<V�D�A�A�3�a�
�c�!�f�-�.�/�<V���(*c3�8# �UHn[U5v� M g7fr��rI�r��es  rr�rK�����@�Z��=��+�+�Z���r�ri�&r6)r+r,�urlparser{r^�upperr_�sortedr>rr�r4r5r7�sha1r��673b2a_base64�digest�r�r;rDr�r��parts�scheme�netlocr�normalized_url�674base_elems�base_string�	key_elemsr}�hashs               rr�r��s3��
�L�L�!�!�#�&�E� ��!�9��F�D��\�\�^�e�+�f�l�l�n�<�t�C�N��J����f�l�l�n�%����n�%�������W�F�:�CS�CS�CU�<V�W�W���(�(�@�Z�@�@�K����^�H�5�6�7�I�
���V�[�[�E��x��r�B�C�675�)�)�I�676�C��8�8�C����[�1�7�<�<�@�D����t�{�{�}�-�c�r�2�2rc	��[RRU5nUSSupgnUR5S-UR5-U-n	/n677U678R	UR55 U679R	U	5 U680R	SR
S[UR55555 SR
SU68155n[R"[RRUSSS	95/nUR	[R"U(a![RRUSSS	9OS68255 SR
U5n
[R"U
[R"U5[R5n[ R""UR%55SS$)
zvCalculates the HMAC-SHA1 OAuth 1.0a signature for the given request.683 684See http://oauth.net/core/1.0a/#signing_process685NrBrCrDc3�X# �UH upUS[[U553v� M" g7frFrHrJs   rr��&_oauth10a_signature.<locals>.<genexpr>�rLrMc3�8# �UHn[U5v� M g7fr�rOrPs  rr�rf�rRrSr��~��saferirTr6)r+r,rUr{r^rVr_rWr>rr��quoter4r5r7rXr�rYrZr[s               rr�r��sa��
�L�L�!�!�#�&�E� ��!�9��F�D��\�\�^�e�+�f�l�l�n�<�t�C�N��J����f�l�l�n�%����n�%�������W�F�:�CS�CS�CU�<V�W�W���(�(�@�Z�@�@�K����V�\�\�/�/��x�0H�s�/�S�T�U�I�
������U�F�L�L�&�&�u�X��S�&�A�PR�S���)�)�I�686�C��8�8�C����[�1�7�<�<�@�D����t�{�{�}�-�c�r�2�2r�valc��[U[5(aURS5n[RRUSS9$)Nzutf-8rhri)�687isinstancerr6r+r,rk)rls rrIrI�s7���#�|�$�$��j�j��!���<�<���c���,�,rr<c��^^�[R"U5n[RR	USS9m[TSSTSSS9nSmUR
UU4SjT55 U$)	NF)�keep_blank_valuesr�r�oauth_token_secretr�)r�rqc3�F># �UHoT;dM688UTUS4v� M g7f)rNr)r�rB�p�specials  ��rr��(_oauth_parse_response.<locals>.<genexpr>�s$����=�q�!�W�,<��!�Q�q�T�!�W��q�s�	!�!)r�689native_strr+r,�parse_qsr|r\)r<�body_strr�rsrts   @@rr�r��sm���� � ��&�H������h�%��@�A��Q�}�%�a�(��3G�1H��1K�L�E�4�G�	�L�L�=�q�=�=��Lr))r�r�r�r7r4r��urllib.parser+r�r��tornadorr�tornado.httputilr�tornado.utilr�tornado.webr�typingrr	r690rrr
rr�rrr�r�rrr&rzr�r�r�rIr�rrr�<module>rs��� 6�p����������'�%�&�C�C�C�	�	�	�~,�~,�BI,�I,�XH,�H,�VZ�:�Z�z1��1�Dj691��j692�b"$�&*�3���c��N�3��3�693
�3��S�#�X��	3�694�D��c��N�#�3��
3�F"$�&*�3���c��N�3��3�695
�3��S�#�X��	3�696�D��c��N�#�3��
3�B-�u�S�%�Z�(�-�S�-����$�s�C�x�.�r
codekingpro/portable-devtools · Team Ai