Ë
    ïñþiA  ã                   ó†   — d Z ddlZddlmZmZmZ ddlmZmZ de	ez  ez  de	fd„Z
de	d	e	defd
„Zdee	z  dz  dedz  fd„Zy)zKUtilities for OAuth 2.0 Resource Indicators (RFC 8707) and PKCE (RFC 7636).é    N)ÚurlparseÚurlsplitÚ
urlunsplit)ÚAnyUrlÚHttpUrlÚurlÚreturnc                 óÌ   — t        | «      }t        |«      }t        |j                  |j                  j                  «       |j                  j                  «       d¬«      «      }|S )aD  Convert server URL to canonical resource URL per RFC 8707.

    RFC 8707 section 2 states that resource URIs "MUST NOT include a fragment component".
    Returns absolute URI with lowercase scheme/host for canonical form.

    Args:
        url: Server URL to convert

    Returns:
        Canonical resource URL string
    Ú )ÚschemeÚnetlocÚfragment)Ústrr   r   Ú_replacer   Úlowerr   )r   Úurl_strÚparsedÚ	canonicals       úU/root/aria/mcps/aria-brain/venv/lib/python3.12/site-packages/mcp/shared/auth_utils.pyÚresource_url_from_server_urlr   	   sV   € ô �#‹h€Gô �gÓ€FÜ˜6Ÿ?™?°&·-±-×2EÑ2EÓ2GÐPV×P]ÑP]×PcÑPcÓPeÐpr˜?ÓsÓt€IàÐó    Úrequested_resourceÚconfigured_resourcec                 ó®  — t        | «      }t        |«      }|j                  j                  «       |j                  j                  «       k7  s5|j                  j                  «       |j                  j                  «       k7  ry|j                  }|j                  }|j                  d«      s|dz  }|j                  d«      s|dz  }|j                  |«      S )a$  Check if a requested resource URL matches a configured resource URL.

    A requested resource matches if it has the same scheme, domain, port,
    and its path starts with the configured resource's path. This allows
    hierarchical matching where a token for a parent resource can be used
    for child resources.

    Args:
        requested_resource: The resource URL being requested
        configured_resource: The resource URL that has been configured

    Returns:
        True if the requested resource matches the configured resource
    Fú/)r   r   r   r   ÚpathÚendswithÚ
startswith)r   r   Ú	requestedÚ
configuredÚrequested_pathÚconfigured_paths         r   Úcheck_resource_allowedr#      sÂ   € ô  Ð+Ó,€IÜÐ-Ó.€Jð ×Ñ×ÑÓ :×#4Ñ#4×#:Ñ#:Ó#<Ò<À	×@PÑ@P×@VÑ@VÓ@XÐ\f×\mÑ\m×\sÑ\sÓ\uÒ@uØð —^‘^€NØ —o‘o€OØ×"Ñ" 3Ô'Ø˜#ÑˆØ×#Ñ# CÔ(Ø˜3Ñˆð ×$Ñ$ _Ó5Ð5r   Ú
expires_inc                 óH   — | €yt        j                   «       t        | «      z   S )zöCalculate token expiry timestamp from expires_in seconds.

    Args:
        expires_in: Seconds until token expiration (may be string from some servers)

    Returns:
        Unix timestamp when token expires, or None if no expiry specified
    N)ÚtimeÚint)r$   s    r   Úcalculate_token_expiryr(   D   s"   € ð ÐØä�9‰9‹;œ˜Z›Ñ(Ð(r   )Ú__doc__r&   Úurllib.parser   r   r   Úpydanticr   r   r   r   Úboolr#   r'   Úfloatr(   © r   r   ú<module>r/      sl   ðÙ Qã ß 7Ñ 7ç $ð c¨G¡m°fÑ&<ð Àó ð,"6¨sð "6Èð "6ÐQUó "6ðJ) s¨S¡y°4Ñ'7ð )¸EÀD¹Lô )r   