+
    P(iT7                         R t ^ RIt^ RIt^ RIt^ RIHt ^ RIHt ^ RIHt ^RI	H
t
 ^RI	Ht RtRtR	tR
tRtRtRR ltRR ltR tR tR tR tR tR tR tR tR tR tR tR# )zauthlib.oauth1.rfc5849.signature.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This module represents a direct implementation of `section 3.4`_ of the spec.

.. _`section 3.4`: https://tools.ietf.org/html/rfc5849#section-3.4
N)to_bytes)
to_unicode)urlparseescape)unescapez	HMAC-SHA1zRSA-SHA1	PLAINTEXTHEADERQUERYBODYc                <   \        W4      p. pV FB  w  rgVR9   d   K  VP                  R4      '       d   \        V4      pVP                  Wg34       KD  	  \	        V4      pRP                  \        V P                  4       4      \        V4      \        V4      .4      # )a  Generate signature base string from request, per `Section 3.4.1`_.

For example, the HTTP request::

    POST /request?b5=%3D%253D&a3=a&c%40=&a2=r%20b HTTP/1.1
    Host: example.com
    Content-Type: application/x-www-form-urlencoded
    Authorization: OAuth realm="Example",
        oauth_consumer_key="9djdj82h48djs9d2",
        oauth_token="kkk9d7dh3k39sjv7",
        oauth_signature_method="HMAC-SHA1",
        oauth_timestamp="137131201",
        oauth_nonce="7d8f3e4a",
        oauth_signature="bYT5CMsGcbgUdFHObYMEfcx6bsw%3D"

    c2&a3=2+q

is represented by the following signature base string (line breaks
are for display purposes only)::

    POST&http%3A%2F%2Fexample.com%2Frequest&a2%3Dr%2520b%26a3%3D2%2520q
    %26a3%3Da%26b5%3D%253D%25253D%26c%2540%3D%26c2%3D%26oauth_consumer_
    key%3D9djdj82h48djs9d2%26oauth_nonce%3D7d8f3e4a%26oauth_signature_m
    ethod%3DHMAC-SHA1%26oauth_timestamp%3D137131201%26oauth_token%3Dkkk
    9d7dh3k39sjv7

.. _`Section 3.4.1`: https://tools.ietf.org/html/rfc5849#section-3.4.1
oauth_&)oauth_signaturerealm)normalize_base_string_uri
startswithr   appendnormalize_parametersjoinr   upper)	methoduriparamshostbase_string_uriunescaped_paramskvnormalized_paramss	   &&&&     f/Users/agent/.openclaw/workspace/venv/lib/python3.14/site-packages/authlib/oauth1/rfc5849/signature.pyconstruct_base_stringr!      s    < 0:O ,, <<!!A'  --=> 886<<>"?#$%	
     c                   \        V 4      p \        P                  ! V 4      w  r#rErgV'       d	   V'       g   \        R4      hV'       g   RpVP                  4       pVP                  4       pVe   VP                  4       pRpRV9   d   VP	                  R^4      w  rW)3V9   d   Tp\        P
                  ! W#WERR34      # )a  Normalize Base String URI per `Section 3.4.1.2`_.

For example, the HTTP request::

    GET /r%20v/X?id=123 HTTP/1.1
    Host: EXAMPLE.COM:80

is represented by the base string URI: "http://example.com/r%20v/X".

In another example, the HTTPS request::

    GET /?q=1 HTTP/1.1
    Host: www.example.net:8080

is represented by the base string URI: "https://www.example.net:8080/".

.. _`Section 3.4.1.2`: https://tools.ietf.org/html/rfc5849#section-3.4.1.2

The host argument overrides the netloc part of the uri argument.
z$uri must include a scheme and netloc/: ))http80)https443)r   r   
ValueErrorlowersplit
urlunparse)
r   r   schemenetlocpathr   queryfragmentdefault_portsports
   &&        r    r   r   V   s    * S/C4<4E4Ec4J1FD% ?@@  \\^F\\^F M f}\\#q)
>]*Fb"EFFr"   c                    V  UUu. uF  w  r\        V4      \        V4      3NK  	  pppVP                  4        V UUu. uF  w  rV RV 2NK  	  pppRP                  V4      # u uppi u uppi )a	  Normalize parameters per `Section 3.4.1.3.2`_.

For example, the list of parameters from the previous section would
be normalized as follows:

Encoded::

+------------------------+------------------+
|          Name          |       Value      |
+------------------------+------------------+
|           b5           |     %3D%253D     |
|           a3           |         a        |
|          c%40          |                  |
|           a2           |       r%20b      |
|   oauth_consumer_key   | 9djdj82h48djs9d2 |
|       oauth_token      | kkk9d7dh3k39sjv7 |
| oauth_signature_method |     HMAC-SHA1    |
|     oauth_timestamp    |     137131201    |
|       oauth_nonce      |     7d8f3e4a     |
|           c2           |                  |
|           a3           |       2%20q      |
+------------------------+------------------+

Sorted::

+------------------------+------------------+
|          Name          |       Value      |
+------------------------+------------------+
|           a2           |       r%20b      |
|           a3           |       2%20q      |
|           a3           |         a        |
|           b5           |     %3D%253D     |
|          c%40          |                  |
|           c2           |                  |
|   oauth_consumer_key   | 9djdj82h48djs9d2 |
|       oauth_nonce      |     7d8f3e4a     |
| oauth_signature_method |     HMAC-SHA1    |
|     oauth_timestamp    |     137131201    |
|       oauth_token      | kkk9d7dh3k39sjv7 |
+------------------------+------------------+

Concatenated Pairs::

+-------------------------------------+
|              Name=Value             |
+-------------------------------------+
|               a2=r%20b              |
|               a3=2%20q              |
|                 a3=a                |
|             b5=%3D%253D             |
|                c%40=                |
|                 c2=                 |
| oauth_consumer_key=9djdj82h48djs9d2 |
|         oauth_nonce=7d8f3e4a        |
|   oauth_signature_method=HMAC-SHA1  |
|      oauth_timestamp=137131201      |
|     oauth_token=kkk9d7dh3k39sjv7    |
+-------------------------------------+

and concatenated together into a single string (line breaks are for
display purposes only)::

    a2=r%20b&a3=2%20q&a3=a&b5=%3D%253D&c%40=&c2=&oauth_consumer_key=9dj
    dj82h48djs9d2&oauth_nonce=7d8f3e4a&oauth_signature_method=HMAC-SHA1
    &oauth_timestamp=137131201&oauth_token=kkk9d7dh3k39sjv7

.. _`Section 3.4.1.3.2`: https://tools.ietf.org/html/rfc5849#section-3.4.1.3.2
=r   )r   sortr   )r   r   r   
key_valuesparameter_partss   &    r    r   r      sq    R 6<<VTQ6!9fQi(VJ<
 OO
 /99jda!AaSzjO9
 88O$$ = :s
   !A%A+c                    V P                   P                  RR4      p\        V P                  V P                  V P
                  V4      # )z,Generate signature base string from request.HostN)headersgetr!   r   r   r   )requestr   s   & r    generate_signature_base_stringr@      s5    ??vt,D gnndSSr"   c                N   T p\        T;'       g    R4      pVR,          pT\        T;'       g    R4      ,          p\        P                  ! \        V4      \        V4      \        P
                  4      p\        P                  ! VP                  4       4      RR p\        V4      # )aC  Generate signature via HMAC-SHA1 method, per `Section 3.4.2`_.

The "HMAC-SHA1" signature method uses the HMAC-SHA1 signature
algorithm as defined in `RFC2104`_::

    digest = HMAC - SHA1(key, text)

.. _`RFC2104`: https://tools.ietf.org/html/rfc2104
.. _`Section 3.4.2`: https://tools.ietf.org/html/rfc5849#section-3.4.2
r&   r   N)
r   hmacnewr   hashlibsha1binascii
b2a_base64digestr   )base_stringclient_secrettoken_secrettextkey	signaturesigs   &&&    r    hmac_sha1_signaturerQ      s    " D $$"
%C 3JC
 6,$$"%%C#EI 

i..0
1#2
6Cc?r"   c                    ^RI Hp \        V 4      p V! \        V 4      V4      p\        P                  ! V4      RR p\        V4      # )aN  Generate signature via RSA-SHA1 method, per `Section 3.4.3`_.

The "RSA-SHA1" signature method uses the RSASSA-PKCS1-v1_5 signature
algorithm as defined in `RFC3447, Section 8.2`_ (also known as
PKCS#1), using SHA-1 as the hash function for EMSA-PKCS1-v1_5.  To
use this method, the client MUST have established client credentials
with the server that included its RSA public key (in a manner that is
beyond the scope of this specification).

.. _`Section 3.4.3`: https://tools.ietf.org/html/rfc5849#section-3.4.3
.. _`RFC3447, Section 8.2`: https://tools.ietf.org/html/rfc3447#section-8.2
)	sign_sha1NrB   )rsarS   r   rG   rH   r   )rJ   rsa_private_keyrS   srP   s   &&   r    rsa_sha1_signaturerW   +  sC     ;'K(;'9A


a
 "
%Cc?r"   c                z    \        T ;'       g    R4      pVR,          pT\        T;'       g    R4      ,          pV# )a  Generate signature via PLAINTEXT method, per `Section 3.4.4`_.

The "PLAINTEXT" method does not employ a signature algorithm.  It
MUST be used with a transport-layer mechanism such as TLS or SSL (or
sent over a secure channel with equivalent protections).  It does not
utilize the signature base string or the "oauth_timestamp" and
"oauth_nonce" parameters.

.. _`Section 3.4.4`: https://tools.ietf.org/html/rfc5849#section-3.4.4
r&   r   r   )rK   rL   rO   s   && r    plaintext_signaturerY   @  sA    " }**+I I
 **++Ir"   c                X    \        V4      p\        W P                  V P                  4      # )zSign a HMAC-SHA1 signature.)r@   rQ   rK   rL   clientr?   rJ   s   && r    sign_hmac_sha1r]   _  s%    09K{,@,@&BUBUVVr"   c                B    \        V4      p\        W P                  4      # )z4Sign a RSASSA-PKCS #1 v1.5 base64 encoded signature.)r@   rW   rsa_keyr[   s   && r    sign_rsa_sha1r`   e  s    09Kk>>::r"   c                B    \        V P                  V P                  4      # )zSign a PLAINTEXT signature.)rY   rK   rL   )r\   r?   s   &&r    sign_plaintextrb   k  s    v33V5H5HIIr"   c                    \        V 4      p\        WP                  V P                  4      p\        P
                  ! W P                  4      # )zVerify a HMAC-SHA1 signature.)r@   rQ   rK   rL   rC   compare_digestrO   )r?   rJ   rP   s   &  r    verify_hmac_sha1re   p  s;    09K
k+@+@'BVBV
WCs$5$566r"   c                    ^RI Hp \        V 4      p\        P                  ! \        V P                  4      4      pV! V\        V4      V P                  4      # )z6Verify a RSASSA-PKCS #1 v1.5 base64 encoded signature.)verify_sha1)rT   rg   r@   rG   
a2b_base64r   rO   rsa_public_key)r?   rg   rJ   rP   s   &   r    verify_rsa_sha1rj   w  sD     09K


hw'8'89
:CsH[173I3IJJr"   c                    \        V P                  V P                  4      p\        P                  ! WP
                  4      # )zVerify a PLAINTEXT signature.)rY   rK   rL   rC   rd   rO   )r?   rP   s   & r    verify_plaintextrl     s1    
g33W5I5I
JCs$5$566r"   )N)__doc__rG   rE   rC   authlib.common.encodingr   r   authlib.common.urlsr   utilr   r   SIGNATURE_HMAC_SHA1SIGNATURE_RSA_SHA1SIGNATURE_PLAINTEXTSIGNATURE_TYPE_HEADERSIGNATURE_TYPE_QUERYSIGNATURE_TYPE_BODYr!   r   r   r@   rQ   rW   rY   r]   r`   rb   re   rj   rl    r"   r    <module>rx      s       , . (  !  !     6rDGNX%vT*Z*>W;J
7K7r"   