xjT/(ddlmZmZmZddlmZmZmZmZm Z m Z m Z dZ edZ ddgZdedefd ZGd d eZGd d eZGddeZGddeZGddeZGddeZGddeZGddeZGddeZy))AnyLiteralcast) AnyHttpUrlAnyUrl BaseModel ConfigDictFieldfield_validatormodel_validator+urn:ietf:params:oauth:grant-type:jwt-bearer)noneclient_secret_postclient_secret_basicprivate_key_jwtauthorization_code refresh_tokenvreturnc|dk(ry|SN)rs c/mnt/ssd/data/Dropbox/adrian/sandbox/mcp-query/venv/lib/python3.12/site-packages/mcp/shared/auth.py_empty_str_to_noners Bw HceZdZUdZeed<dZeded<dZe dzed<dZ edzed<dZ edzed<e dd e d edzd edzfd Zy) OAuthTokenz=See https://datatracker.ietf.org/doc/html/rfc6749#section-5.1 access_tokenBearer token_typeN expires_inscoperbeforemoderrcFt|tr|jS|SN) isinstancestrtitleclsrs rnormalize_token_typezOAuthToken.normalize_token_type#s! a 779 r)__name__ __module__ __qualname____doc__r*__annotations__r!rr"intr#rr classmethodr.rrrrrs{G$,J!,!Jd !E3: $M3:$\1S4ZC$J2rrcDeZdZUdZeed<dZedzed<dZedzed<y)AuthorizationCodeResultaAuthorization-code-grant redirect parameters returned by a callback handler. `iss` carries the RFC 9207 authorization-response issuer when the authorization server includes it in the redirect; the client validates it against the expected issuer. codeNstateiss)r/r0r1r2r*r3r9r:rrrr7r7-s* IE3:Ctrr7ceZdZdefdZy)InvalidScopeErrormessagec||_yr(r=selfr=s r__init__zInvalidScopeError.__init__:  rNr/r0r1r*rBrrrr<r<9rr<ceZdZdefdZy)InvalidRedirectUriErrorr=c||_yr(r?r@s rrBz InvalidRedirectUriError.__init__?rCrNrDrrrrGrG>rErrGcXeZdZUdZedZdgZeee d<dZ edze d<dZ edze d<dZ e dze d <dZe dze d <dZeedze d <dZe dze d <dZe dze d <dZe dze d<dZedze d<dZedze d<dZedze d<ed d d d ddededefdZy)OAuthClientMetadataBaseaRFC 7591 OAuth 2.0 Dynamic Client Registration metadata shared verbatim by the registration request (`OAuthClientMetadata`) and the authorization server's record of a registered client (`OAuthClientInformationFull`). Fields whose acceptable values differ between the two - what this SDK sends versus what a third-party server may echo - are declared on each model rather than here. See https://datatracker.ietf.org/doc/html/rfc7591#section-2 Turl_preserve_empty_pathr8response_typesNr# client_name client_urilogo_uricontactstos_uri policy_urijwks_urijwks software_idsoftware_versionr$r%rrct|Sr()rr,s r"_empty_string_optional_url_to_nonez:OAuthClientMetadataBase._empty_string_optional_url_to_none`s"!$$r)r/r0r1r2r model_configrMlistr*r3r#rNrOrrPrQrRrSrTrUrrVrWr r5objectrYrrrrJrJCs d;L"(NDI(E3:#Kt"$(J T!("&Hj4&!%Hd3i$%!%GZ$ %$(J T!("&Hj4&D#*"Kt"#'cDj'  %6%f%%rrJceZdZUdZeddZeedzed<dZ e dzed<ee Z ee dezed <d Ze d ed <y) OAuthClientMetadataaMRFC 7591 OAuth 2.0 Dynamic Client Registration request metadata: what an MCP client sends when it registers. Field values are narrowed to what this SDK will put on the wire; parsing the authorization server's response is `OAuthClientInformationFull`'s job. See https://datatracker.ietf.org/doc/html/rfc7591#section-2 . min_lengthN redirect_uristoken_endpoint_auth_method)rrr grant_typesnative)webreapplication_type)r/r0r1r2r rbr[rr3rcTokenEndpointAuthMethodDEFAULT_GRANT_TYPESrdrr*rgrrrr^r^osq */sq)AM4<$&AAE 7$ >E !dehkk" 2:go.9rr^c8eZdZUdZdZeedzed<dZe dzed<ee Z ee ed<dZ e dzed<e ed<dZ e dzed<dZedzed <dZedzed <dZe dzed <ed ededefdZde dzdee dzfdZdedzdefdZy)OAuthClientInformationFullaRFC 7591 OAuth 2.0 Dynamic Client Registration client information response (client information plus metadata) - the authorization server's record of a registered client. See https://datatracker.ietf.org/doc/html/rfc7591#section-3.2.1 A third-party authorization server "MAY reject or replace any of the client's requested metadata values submitted during the registration and substitute them with suitable values", so `application_type`, `token_endpoint_auth_method`, and `grant_types` are typed to accept any string the server echoes, and `redirect_uris` may be absent or empty. A member the server serializes as a placeholder - an explicit `null`, or `""` - is read as an omitted key, so the field's default applies rather than the parse failing. Whether a substituted value is usable is decided where the value is used, not at parse. `redirect_uris` elements are still parsed as URLs, as the authorization server compares them against a client's requested `redirect_uri`. Nrbrcrdrg client_id client_secretclient_id_issued_atclient_secret_expires_atissuerr$r%datarct|trJttttf|}|j Dcic]\}}| |dk7s||c}}S|Scc}}wr)r)dictrr*ritems)r-rqmemberskeyvalues r$_placeholder_members_read_as_omittedz?OAuthClientInformationFull._placeholder_members_read_as_omittedsZ dD !4S>40G18f:3EDUZ_ceZeCJf f gs A AArequested_scopec|y|jd}|jgn|jjd}|D]}||vstd||S)N z%Client was not registered with scope )splitr#r<)rAryrequested_scopesallowed_scopesr#s rvalidate_scopez)OAuthClientInformationFull.validate_scopesp  "*005#zz1tzz7G7G7L% YEN*'*OPUw(WXX Y r redirect_uric|+|jr||jvrtd|d|S|jr't|jdk(r|jdStd)NzRedirect URI 'z' not registered for clientr_rzOredirect_uri must be specified unless the client has exactly one registered URI)rbrGlen)rArs rvalidate_redirect_uriz0OAuthClientInformationFull.validate_redirect_urisu  #%%T=O=O)O-|nLg.hii    C(:(:$;q$@%%a( ()a r)r/r0r1r2rbr[rr3rcr*rirdrgrmrnr4rorpr r5r\rxrrrrrrkrks *.M4<$&-.2d 1!"56Kc6$(cDj'N $M3:$&*t*+/cDj/FC$J(#6$ cDj T#Y=M  &4- F rrkc0eZdZUdZedZeed<eed<eed<dZedzed<dZ e e dzed <d gZ e e ed <dZ e e dzed <dZe e dzed <dZe e dzed<dZe e dzed<dZedzed<dZe e dzed<dZedzed<dZedzed<dZedzed<dZe e dzed<dZe e dzed<dZedzed<dZe e dzed<dZe e dzed<dZe e dzed<dZedzed<dZedzed<dZe e dzed<y) OAuthMetadatazvRFC 8414 OAuth 2.0 Authorization Server Metadata. See https://datatracker.ietf.org/doc/html/rfc8414#section-2 TrKrpauthorization_endpointtoken_endpointNregistration_endpointscopes_supportedr8response_types_supportedresponse_modes_supportedgrant_types_supported%token_endpoint_auth_methods_supported0token_endpoint_auth_signing_alg_values_supportedservice_documentationui_locales_supported op_policy_uri op_tos_urirevocation_endpoint*revocation_endpoint_auth_methods_supported5revocation_endpoint_auth_signing_alg_values_supportedintrospection_endpoint-introspection_endpoint_auth_methods_supported8introspection_endpoint_auth_signing_alg_values_supported code_challenge_methods_supported%client_id_metadata_document_supported.authorization_response_iss_parameter_supported&authorization_grant_profiles_supported) r/r0r1r2r rZrr3rrr[r*rrrrrrrrrrrrrrrrrboolrrrrrrrsd;L &&/3:,3)-d3i$&-+1(d3i215d3i$.5.249t+2>B)49t+;BIM4d3i$6FM/3:,3-1$s)d*1'+M:$+$(J T!(-1d*1CG.S D0@GNR949t;KR04J-4FJ149t3CJQUNU9=$d3i$&6=9=)4$;=BF2D4KF@D*DI,<CrrcpeZdZUdZedZeed<eddZ e eed<d Z ed zed <d Z e e d zed <ed g Ze e d zed<d Ze e d zed<d Ze d zed<d Zed zed<d Zed zed<d Zed zed<d Zed zed<d Ze e d zed<d Ze e d zed<d Zed zed<y )ProtectedResourceMetadataztRFC 9728 OAuth 2.0 Protected Resource Metadata. See https://datatracker.ietf.org/doc/html/rfc9728#section-2 TrKresource.r_r`authorization_serversNrTrheader)defaultbearer_methods_supported%resource_signing_alg_values_supported resource_nameresource_documentationresource_policy_uriresource_tos_uri*tls_client_certificate_bound_access_tokens%authorization_details_types_supported!dpop_signing_alg_values_supported!dpop_bound_access_tokens_required)r/r0r1r2r rZrr3r rr[rTrr*rrrrrrrrrrrrrrrrsd;L.3CA.F4 +F"&Hj4&)-d3i$&-16z1Jd3i$.J>B)49t+;B $M3:$04J-4-1d*1*.j4'.>B.t B>B)49t+;B:>%tCy4'7>59%td{9rrN)typingrrrpydanticrrrr r r r JWT_BEARER_GRANT_TYPErhrir\rrr7 Exceptionr<rGrJr^rkrrrrrrs%%gggF ""hi,_= & V & i   i )%i)%X:1:&D!8DN DI DF: :r