+
    P(¸i!  ã                   óp   € ^ RI Ht ^ RIHt ^ RIHt ^ RIHt ^ RIHt ^ RI	H
t
 ^RIHt  ! R R	]4      tR
# )é    )ÚContinueIteration)Údefault_json_headers)ÚExpiredTokenError)ÚInvalidClaimError)ÚInvalidTokenError)ÚJWTBearerTokenValidator)ÚIntrospectionEndpointc                   óh   a a€ ] tR t^t oRtRtRV 3R lltR tR tR t	R t
V3R lR	 ltR
tVtV ;t# )ÚJWTIntrospectionEndpointa¨  JWTIntrospectionEndpoint inherits from :ref:`specs/rfc7662`
:class:`~authlib.oauth2.rfc7662.IntrospectionEndpoint` and implements the machinery
to automatically process the JWT access tokens.

:param issuer: The issuer identifier for which tokens will be introspected.

:param \\*\\*kwargs: Other parameters are inherited from
    :class:`~authlib.oauth2.rfc7662.introspection.IntrospectionEndpoint`.

::

    class MyJWTAccessTokenIntrospectionEndpoint(JWTIntrospectionEndpoint):
        def get_jwks(self): ...

        def get_username(self, user_id): ...


    # endpoint dedicated to JWT access token introspection
    authorization_server.register_endpoint(
        MyJWTAccessTokenIntrospectionEndpoint(
            issuer="https://authorization-server.example.org",
        )
    )

    # another endpoint dedicated to refresh token introspection
    authorization_server.register_endpoint(MyRefreshTokenIntrospectionEndpoint)

Úintrospectionc                ó8   <€ \         SV `  ! VR V/VB  Wn        R# )ÚserverN)ÚsuperÚ__init__Úissuer)Úselfr   r   ÚargsÚkwargsÚ	__class__s   &&&*,€Új/Users/agent/.openclaw/workspace/venv/lib/python3.14/site-packages/authlib/oauth2/rfc9068/introspection.pyr   Ú!JWTIntrospectionEndpoint.__init__,   s   ø€ Ü‰Ò˜$Ð8 vÐ8°Ò8ØŽó    c                óz   € V P                  V4      pV P                  W4      pV P                  V4      p^ÈV\        3# )Ú )Úauthenticate_endpoint_clientÚauthenticate_tokenÚcreate_introspection_payloadr   )r   ÚrequestÚclientÚtokenÚbodys   &&   r   Úcreate_endpoint_responseÚ1JWTIntrospectionEndpoint.create_endpoint_response0   sF   € ð ×2Ñ2°7Ó;ˆð ×'Ñ'¨Ó8ˆð ×0Ñ0°Ó7ˆØDÔ.Ð.Ð.r   c                ó–  € V P                  W4       VP                  P                  R4      R9  d   \        4       h\	        V P
                  RR7      pV P                  Vn         VP                  VP                  R,          4      pT'       d   T P                  YBT4      '       d   T# R# R#   \         d   p\        4       ThRp?ii ; i)r   Útoken_type_hintN)r   Úresource_serverr    )Úaccess_tokenN)
Úcheck_paramsÚformÚgetr   r   r   Úget_jwksr   r   Úcheck_permission)r   r   r   Ú	validatorr    Úexcs   &&&   r   r   Ú+JWTIntrospectionEndpoint.authenticate_token=   s°   € à×Ñ˜'Ô*ð <‰<×ÑÐ-Ó.Ð6LÔLÜ#Ó%Ð%ä+°4·;±;ÐPTÔUˆ	Ø!Ÿ]™]ˆ	Ôð	/Ø×0Ñ0°·±¸gÕ1FÓGˆE÷ T×*Ñ*¨5¸'×BÒBØˆLñ C‰5øô !ô 	/Ü#Ó%¨3Ð.ûð	/ús   Á%"B- Â-CÂ8CÃCc                ó¦  € V'       g   R R/#  VP                  4        R RRRRTR,          RTR,          R	TR	,          R
TR
,          RTR,          RTR,          RTR,          /	pT P                  TR	,          4      ;p'       d   YCR&   T#   \         d    R R/u # \         d-   pTP                  R8X  d   \	        4       Th\        4       ThRp?ii ; i)ÚactiveFÚissNTÚ
token_typeÚBearerÚ	client_idÚscopeÚsubÚaudÚexpÚiatÚusername)Úvalidater   r   Ú
claim_namer   r   Úget_username)r   r    r.   Úpayloadr;   s   &&   r   r   Ú5JWTIntrospectionEndpoint.create_introspection_payloadQ   sâ   € ßØ˜eÐ$Ð$ð	/ØN‰NÔð dØ˜(Ø˜˜{Õ+ØU˜7•^Ø5˜•<Ø5˜•<Ø5˜•<Ø5˜•<Ø5˜•<ð

ˆð ×(Ñ(¨¨u­Ó6Ð6ˆ8Ö6Ø"*JÑàˆøô- !ô 	%Ø˜eÐ$Ò$Ü ô 	/Ø~‰~ Ô&Ü'Ó)¨sÐ2Ü#Ó%¨3Ð.ûð	/ús#   ŽB	 Â	CÂCÂ#CÂ$'CÃCc                ó   € \        4       h)zµReturn the JWKs that will be used to check the JWT access token signature.
Developers MUST re-implement this method::

    def get_jwks(self):
        return load_jwks("jwks.json")
)ÚNotImplementedError)r   s   &r   r+   Ú!JWTIntrospectionEndpoint.get_jwkso   s   € ô "Ó#Ð#r   c                ó&   <€ V ^8„  d   QhRS[ RS[ /# )é   Úuser_idÚreturn)Ústr)ÚformatÚ__classdict__s   "€r   Ú__annotate__Ú%JWTIntrospectionEndpoint.__annotate__x   s   ø€ ÷ ñ ¡Cð ©Cñ r   c                ó   € R# )z¡Returns an username from a user ID.
Developers MAY re-implement this method::

    def get_username(self, user_id):
        return User.get(id=user_id).username
N© )r   rF   s   &&r   r>   Ú%JWTIntrospectionEndpoint.get_usernamex   s   € ñ r   )r   )N)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__ÚENDPOINT_NAMEr   r"   r   r   r+   r>   Ú__static_attributes__Ú__classdictcell__Ú__classcell__)r   rJ   s   @@r   r   r      s9   ù‡ € ñð< $€M÷ò/òò(ò<$÷÷ ð r   r   N)Úauthlib.common.errorsr   Úauthlib.constsr   Úauthlib.jose.errorsr   r   Úauthlib.oauth2.rfc6750.errorsr   Ú&authlib.oauth2.rfc9068.token_validatorr   Úrfc7662r	   r   rN   r   r   Ú<module>r_      s)   ðÝ 3Ý /Ý 1Ý 1Ý ;Ý Jå +ôtÐ4ö tr   