
    qh2                        S r SSKrSSKJrJr   " S S\5      r " S S\5      r " S S	\5      r " S
 S\5      r	 " S S\5      r
 " S S\5      r " S S\5      r " S S\5      r " S S\5      r " S S\5      r " S S\5      r " S S\5      r " S S\5      r " S S\5      r " S  S!\5      r " S" S#\5      r " S$ S%\5      r " S& S'\5      r " S( S)\5      r " S* S+\5      r " S, S-\5      r " S. S/\5      r " S0 S1\5      r " S2 S3\5      r " S4 S5\5      r " S6 S7\5      r " S8 S9\5      r  " S: S;\5      r! " S< S=\5      r" " S> S?\5      r# " S@ SA\5      r$ " SB SC\5      r% " SD SE\5      r& " SF SG\5      r'SISH jr(g)Jz
oauthlib.oauth2.rfc6749.errors
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Error used both by OAuth 2 clients and providers to represent the spec
defined error responses for all four core grant types.
    N)add_params_to_uri	urlencodec                      ^  \ rS rSrSrSrSr  SU 4S jjrS r\	S 5       r
\	S 5       r\	S	 5       r\	S
 5       rSrU =r$ )OAuth2Error   N   c                 F  > Ub  Xl         SR                  U R                  U R                   5      nU(       a  US[        U5      -   -  n[        TU ]  U5        X l        X0l        U(       a  X@l        U(       a  UR                  U l	        UR                  U l
        UR                  U l        UR                  U l        UR                  U l        UR                  U l        U(       d  UR                  U l        ggSU l	        SU l
        SU l        SU l        SU l        SU l        g)a  
:param description: A human-readable ASCII [USASCII] text providing
                    additional information, used to assist the client
                    developer in understanding the error that occurred.
                    Values for the "error_description" parameter
                    MUST NOT include characters outside the set
                    x20-21 / x23-5B / x5D-7E.

:param uri: A URI identifying a human-readable web page with information
            about the error, used to provide the client developer with
            additional information about the error.  Values for the
            "error_uri" parameter MUST conform to the URI- Reference
            syntax, and thus MUST NOT include characters outside the set
            x21 / x23-5B / x5D-7E.

:param state: A CSRF protection value received from the client.

:param status_code:

:param request: OAuthlib request.
:type request: oauthlib.common.Request
Nz({}) {} )descriptionformaterrorreprsuper__init__uristatestatus_coderedirect_uri	client_idscopesresponse_typeresponse_mode
grant_type)selfr   r   r   r   requestmessage	__class__s          P/var/www/html/env/lib/python3.13/site-packages/oauthlib/oauth2/rfc6749/errors.pyr   OAuth2Error.__init__   s    0 "*""4::t/?/?@sT']**G!
* ' 4 4D$..DN!..DK!(!6!6D!(!6!6D%00DO$]]
  !%D!DNDK!%D!%D"DO    c                 L    U R                   S:H  n[        XR                  U5      $ )Nfragment)r   r   	twotuples)r   r   r#   s      r   in_uriOAuth2Error.in_uriI   s#    %%3 nnh??r!   c                 8   SU R                   4/nU R                  (       a  UR                  SU R                  45        U R                  (       a  UR                  SU R                  45        U R                  (       a  UR                  SU R                  45        U$ )Nr   error_description	error_urir   )r   r   appendr   r   )r   r   s     r   r$   OAuth2Error.twotuplesM   sq    4::&'LL-t/?/?@A88LL+txx01::LL'4::./r!   c                 ,    [        U R                  5      $ N)r   r$   r   s    r   
urlencodedOAuth2Error.urlencodedX   s    ((r!   c                 T    [         R                  " [        U R                  5      5      $ r-   )jsondumpsdictr$   r.   s    r   r2   OAuth2Error.json\   s    zz$t~~.//r!   c                 x   U R                   S:X  a   SR                  U R                  5      /nU R                  (       a*  UR	                  SR                  U R                  5      5        U R
                  (       a*  UR	                  SR                  U R
                  5      5        SSSR                  U5      -   0$ 0 $ )N  z
error="{}"zerror_description="{}"zerror_uri="{}"zWWW-AuthenticatezBearer z, )r   r   r   r   r*   r   join)r   
authvaluess     r   headersOAuth2Error.headers`   s    s" '--djj9:J!!":"A"A$BRBR"STxx!!"2"9"9$(("CD&	DIIj4I(IJJ	r!   )
r   r   r   r   r   r   r   r   r   r   )NNNNN)__name__
__module____qualname____firstlineno__r   r   r   r   r%   propertyr$   r/   r2   r:   __static_attributes____classcell__r   s   @r   r   r      st    EKK9=+/5#n@   ) ) 0 0  r!   r   c                       \ rS rSrSrSrg)TokenExpiredErrors   token_expired Nr<   r=   r>   r?   r   rA   rH   r!   r   rE   rE   s       Er!   rE   c                       \ rS rSrSrSrSrg)InsecureTransportErrorw   insecure_transportzOAuth 2 MUST utilize https.rH   Nr<   r=   r>   r?   r   r   rA   rH   r!   r   rL   rL   w   s     E/Kr!   rL   c                       \ rS rSrSrSrSrg)MismatchingStateError|   mismatching_statez6CSRF Warning! State not equal in request and response.rH   NrO   rH   r!   r   rQ   rQ   |   s    EJKr!   rQ   c                       \ rS rSrSrSrg)MissingCodeError   missing_coderH   NrI   rH   r!   r   rU   rU      s    Er!   rU   c                       \ rS rSrSrSrg)MissingTokenError   missing_tokenrH   NrI   rH   r!   r   rY   rY      rJ   r!   rY   c                       \ rS rSrSrSrg)MissingTokenTypeError   missing_token_typerH   NrI   rH   r!   r   r]   r]      s     Er!   r]   c                       \ rS rSrSrSrg)FatalClientError   a  
Errors during authorization where user should not be redirected back.

If the request fails due to a missing, invalid, or mismatching
redirection URI, or if the client identifier is missing or invalid,
the authorization server SHOULD inform the resource owner of the
error and MUST NOT automatically redirect the user-agent to the
invalid redirection URI.

Instead the user should be informed of the error by the provider itself.
rH   N)r<   r=   r>   r?   __doc__rA   rH   r!   r   ra   ra      s    
 	r!   ra   c                       \ rS rSrSrSrSrg)InvalidRequestFatalError   z
For fatal errors, the request is missing a required parameter, includes
an invalid parameter value, includes a parameter more than once, or is
otherwise malformed.
invalid_requestrH   Nr<   r=   r>   r?   rc   r   rA   rH   r!   r   re   re          
 Er!   re   c                       \ rS rSrSrSrg)InvalidRedirectURIError   zInvalid redirect URI.rH   Nr<   r=   r>   r?   r   rA   rH   r!   r   rk   rk          )Kr!   rk   c                       \ rS rSrSrSrg)MissingRedirectURIError   zMissing redirect URI.rH   Nrm   rH   r!   r   rp   rp      rn   r!   rp   c                       \ rS rSrSrSrg)MismatchingRedirectURIError   zMismatching redirect URI.rH   Nrm   rH   r!   r   rs   rs      s    -Kr!   rs   c                       \ rS rSrSrSrg)InvalidClientIdError   z"Invalid client_id parameter value.rH   Nrm   rH   r!   r   rv   rv      s    6Kr!   rv   c                       \ rS rSrSrSrg)MissingClientIdError   zMissing client_id parameter.rH   Nrm   rH   r!   r   ry   ry      s    0Kr!   ry   c                       \ rS rSrSrSrSrg)InvalidRequestError   z
The request is missing a required parameter, includes an invalid
parameter value, includes a parameter more than once, or is
otherwise malformed.
rg   rH   Nrh   rH   r!   r   r|   r|      ri   r!   r|   c                       \ rS rSrSrSrg)MissingResponseTypeError   z Missing response_type parameter.rH   Nrm   rH   r!   r   r   r      s    4Kr!   r   c                       \ rS rSrSrSrSrg)MissingCodeChallengeError   a  
If the server requires Proof Key for Code Exchange (PKCE) by OAuth
public clients and the client does not send the "code_challenge" in
the request, the authorization endpoint MUST return the authorization
error response with the "error" value set to "invalid_request".  The
"error_description" or the response of "error_uri" SHOULD explain the
nature of error, e.g., code challenge required.
zCode challenge required.rH   Nr<   r=   r>   r?   rc   r   rA   rH   r!   r   r   r      s     -Kr!   r   c                       \ rS rSrSrSrSrg)MissingCodeVerifierError   zf
The request to the token endpoint, when PKCE is enabled, has
the parameter `code_verifier` REQUIRED.
zCode verifier required.rH   Nr   rH   r!   r   r   r      s     ,Kr!   r   c                       \ rS rSrSrSrSrg)AccessDeniedError   z@
The resource owner or authorization server denied the request.
access_deniedrH   Nrh   rH   r!   r   r   r      s     Er!   r   c                       \ rS rSrSrSrSrg)UnsupportedResponseTypeError   z^
The authorization server does not support obtaining an authorization
code using this method.
unsupported_response_typerH   Nrh   rH   r!   r   r   r      s     (Er!   r   c                       \ rS rSrSrSrSrg)#UnsupportedCodeChallengeMethodError   aH  
If the server supporting PKCE does not support the requested
transformation, the authorization endpoint MUST return the
authorization error response with "error" value set to
"invalid_request".  The "error_description" or the response of
"error_uri" SHOULD explain the nature of error, e.g., transform
algorithm not supported.
z"Transform algorithm not supported.rH   Nr   rH   r!   r   r   r      s     7Kr!   r   c                       \ rS rSrSrSrSrg)InvalidScopeError   z
The requested scope is invalid, unknown, or malformed, or
exceeds the scope granted by the resource owner.

https://tools.ietf.org/html/rfc6749#section-5.2
invalid_scoperH   Nrh   rH   r!   r   r   r      s     Er!   r   c                       \ rS rSrSrSrSrg)ServerError   z
The authorization server encountered an unexpected condition that
prevented it from fulfilling the request.  (This error code is needed
because a 500 Internal Server Error HTTP status code cannot be returned
to the client via a HTTP redirect.)
server_errorrH   Nrh   rH   r!   r   r   r      s     Er!   r   c                       \ rS rSrSrSrSrg)TemporarilyUnavailableErrori	  a  
The authorization server is currently unable to handle the request
due to a temporary overloading or maintenance of the server.
(This error code is needed because a 503 Service Unavailable HTTP
status code cannot be returned to the client via a HTTP redirect.)
temporarily_unavailablerH   Nrh   rH   r!   r   r   r   	  s     &Er!   r   c                        \ rS rSrSrSrSrSrg)InvalidClientErrori  a  
Client authentication failed (e.g. unknown client, no client
authentication included, or unsupported authentication method).
The authorization server MAY return an HTTP 401 (Unauthorized) status
code to indicate which HTTP authentication schemes are supported.
If the client attempted to authenticate via the "Authorization" request
header field, the authorization server MUST respond with an
HTTP 401 (Unauthorized) status code, and include the "WWW-Authenticate"
response header field matching the authentication scheme used by the
client.
invalid_clientr7   rH   Nr<   r=   r>   r?   rc   r   r   rA   rH   r!   r   r   r     s    
 EKr!   r   c                        \ rS rSrSrSrSrSrg)InvalidGrantErrori#  a  
The provided authorization grant (e.g. authorization code, resource
owner credentials) or refresh token is invalid, expired, revoked, does
not match the redirection URI used in the authorization request, or was
issued to another client.

https://tools.ietf.org/html/rfc6749#section-5.2
invalid_grantr   rH   Nr   rH   r!   r   r   r   #  s     EKr!   r   c                       \ rS rSrSrSrSrg)UnauthorizedClientErrori0  zR
The authenticated client is not authorized to use this authorization
grant type.
unauthorized_clientrH   Nrh   rH   r!   r   r   r   0  s     "Er!   r   c                       \ rS rSrSrSrSrg)UnsupportedGrantTypeErrori8  zL
The authorization grant type is not supported by the authorization
server.
unsupported_grant_typerH   Nrh   rH   r!   r   r   r   8  s     %Er!   r   c                       \ rS rSrSrSrSrg)UnsupportedTokenTypeErrori@  z
The authorization server does not support the hint of the
presented token type.  I.e. the client tried to revoke an access token
on a server not supporting this feature.
unsupported_token_typerH   Nrh   rH   r!   r   r   r   @  s    
 %Er!   r   c                   $    \ rS rSrSrSrSrSrSrg)InvalidTokenErroriI  z
The access token provided is expired, revoked, malformed, or
invalid for other reasons.  The resource SHOULD respond with
the HTTP 401 (Unauthorized) status code.  The client MAY
request a new access token and retry the protected resource
request.
invalid_tokenr7   zWThe access token provided is expired, revoked, malformed, or invalid for other reasons.rH   N	r<   r=   r>   r?   rc   r   r   r   rA   rH   r!   r   r   r   I  s     EK3Kr!   r   c                   $    \ rS rSrSrSrSrSrSrg)InsufficientScopeErroriW  z
The request requires higher privileges than provided by the
access token.  The resource server SHOULD respond with the HTTP
403 (Forbidden) status code and MAY include the "scope"
attribute with the scope necessary to access the protected
resource.
insufficient_scopei  zIThe request requires higher privileges than provided by the access token.rH   Nr   rH   r!   r   r   r   W  s     !EK'Kr!   r   c                       \ rS rSrSrSrSrg)ConsentRequiredie  a  
The Authorization Server requires End-User consent.

This error MAY be returned when the prompt parameter value in the
Authentication Request is none, but the Authentication Request cannot be
completed without displaying a user interface for End-User consent.
consent_requiredrH   Nrh   rH   r!   r   r   r   e  s     Er!   r   c                       \ rS rSrSrSrSrg)LoginRequiredip  a  
The Authorization Server requires End-User authentication.

This error MAY be returned when the prompt parameter value in the
Authentication Request is none, but the Authentication Request cannot be
completed without displaying a user interface for End-User authentication.
login_requiredrH   Nrh   rH   r!   r   r   r   p  s     Er!   r   c                   ,   ^  \ rS rSrSrU 4S jrSrU =r$ )CustomOAuth2Errori{  z
This error is a placeholder for all custom errors not described by the RFC.
Some of the popular OAuth2 providers are using custom errors.
c                 2   > Xl         [        TU ]  " U0 UD6  g r-   )r   r   r   )r   r   argskwargsr   s       r   r   CustomOAuth2Error.__init__  s    
$)&)r!   )r   )r<   r=   r>   r?   rc   r   rA   rB   rC   s   @r   r   r   {  s    * *r!   r   c                 .   SS K nSS KnUR                  S5      UR                  S5      UR                  S5      S.nUR                  UR                  [
           UR                  5       H  u  pVUR                  U :X  d  M  U" S0 UD6e   [        SSU 0UD6e)Nr   r(   r)   r   )r   r   r   r   rH   )	inspectsysget
getmembersmodulesr<   isclassr   r   )r   paramsr   r   r   _clss          r   raise_from_errorr     s    zz"56zz+&G$F
 $$S[[%:GOOL99-- M 
2%
26
22r!   r-   ))rc   r2   oauthlib.commonr   r   	Exceptionr   rE   rL   rQ   rU   rY   r]   ra   re   rk   rp   rs   rv   ry   r|   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   rH   r!   r   <module>r      s    8c) cL 0[ 0
KK K
{  !K !	{ 	/ *6 **6 *.": .73 713 1+ 52 5	- 3 	-,2 , (; (	7*= 	7 + &+ &)  
 
"k "% %% %4 4([ (k K * *3r!   