U
    Æ½„b÷  ã                	   @   s–   d dl Z d dlmZ d dl mZmZmZ ddlmZ ddl	m
Z
 zd dl mZ dZW n ek
rl   d	ZY nX d
ddddddddh	ZG dd„ dƒZdS )é    N)Úgettext_lazy)ÚInvalidAlgorithmErrorÚInvalidTokenErrorÚ
algorithmsé   )ÚTokenBackendError)Úformat_lazy)ÚPyJWKClientTFZHS256ZHS384ZHS512ZRS256ZRS384ZRS512ZES256ZES384ZES512c                   @   s>   e Zd Zdedœdd„Zdd„ Zd	d
„ Zdd„ Zddd„ZdS )ÚTokenBackendNÚ r   )Újwk_urlc                 C   sP   |   |¡ || _|| _|| _|| _|| _tr@|r8t|ƒnd | _nd | _|| _	d S )N)
Ú_validate_algorithmÚ	algorithmÚsigning_keyÚverifying_keyÚaudienceÚissuerÚJWK_CLIENT_AVAILABLEr	   Újwks_clientÚleeway)Úselfr   r   r   r   r   r   r   © r   úE/tmp/pip-unpacked-wheel-cvqxdfy5/rest_framework_simplejwt/backends.pyÚ__init__   s    

zTokenBackend.__init__c                 C   s@   |t krtttdƒ|ƒƒ‚|tjkr<tjs<tttdƒ|ƒƒ‚dS )z”
        Ensure that the nominated algorithm is recognized, and that cryptography is installed for those
        algorithms that require it
        z Unrecognized algorithm type '{}'z/You must have cryptography installed to use {}.N)ÚALLOWED_ALGORITHMSr   r   Ú_r   Zrequires_cryptographyZ
has_crypto)r   r   r   r   r   r   5   s    ÿ ÿÿz TokenBackend._validate_algorithmc                 C   s,   | j  d¡r| jS | jr&| j |¡jS | jS )NZHS)r   Ú
startswithr   r   Zget_signing_key_from_jwtÚkeyr   )r   Útokenr   r   r   Úget_verifying_keyF   s
    zTokenBackend.get_verifying_keyc                 C   s\   |  ¡ }| jdk	r| j|d< | jdk	r0| j|d< tj|| j| jd�}t|tƒrX| 	d¡S |S )zL
        Returns an encoded token for the given payload dictionary.
        NZaudZiss)r   zutf-8)
Úcopyr   r   ÚjwtÚencoder   r   Ú
isinstanceÚbytesÚdecode)r   ÚpayloadZjwt_payloadr   r   r   r   r"   O   s    





zTokenBackend.encodeTc              
   C   sŠ   z6t j||  |¡| jg| j| j| j| jdk	|dœd�W S  tk
rf } ztt	dƒƒ|‚W 5 d}~X Y n  t
k
r„   tt	dƒƒ‚Y nX dS )zý
        Performs a validation of the given token and returns its payload
        dictionary.

        Raises a `TokenBackendError` if the token is malformed, if its
        signature check fails, or if its 'exp' claim indicates it has expired.
        N)Z
verify_audZverify_signature)r   r   r   r   ÚoptionszInvalid algorithm specifiedzToken is invalid or expired)r!   r%   r   r   r   r   r   r   r   r   r   )r   r   ÚverifyÚexr   r   r   r%   `   s     þùzTokenBackend.decode)Nr   NNNr   )T)	Ú__name__Ú
__module__Ú__qualname__Ústrr   r   r   r"   r%   r   r   r   r   r
      s         øù	r
   )r!   Zdjango.utils.translationr   r   r   r   r   Ú
exceptionsr   Úutilsr   r	   r   ÚImportErrorr   r
   r   r   r   r   Ú<module>   s(   
÷