Library update
This commit is contained in:
@@ -0,0 +1,155 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from __future__ import absolute_import
|
||||
|
||||
"""
|
||||
oauthlib.common
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
This module provides data structures and utilities common
|
||||
to all implementations of OAuth.
|
||||
"""
|
||||
|
||||
import re
|
||||
import urllib
|
||||
import urlparse
|
||||
|
||||
|
||||
always_safe = (u'ABCDEFGHIJKLMNOPQRSTUVWXYZ'
|
||||
u'abcdefghijklmnopqrstuvwxyz'
|
||||
u'0123456789' u'_.-')
|
||||
|
||||
|
||||
def quote(s, safe=u'/'):
|
||||
encoded = s.encode("utf-8")
|
||||
quoted = urllib.quote(encoded, safe)
|
||||
return quoted.decode("utf-8")
|
||||
|
||||
|
||||
def unquote(s):
|
||||
encoded = s.encode("utf-8")
|
||||
unquoted = urllib.unquote(encoded)
|
||||
return unquoted.decode("utf-8")
|
||||
|
||||
|
||||
def urlencode(params):
|
||||
utf8_params = encode_params_utf8(params)
|
||||
urlencoded = urllib.urlencode(utf8_params)
|
||||
return urlencoded.decode("utf-8")
|
||||
|
||||
|
||||
def encode_params_utf8(params):
|
||||
"""Ensures that all parameters in a list of 2-element tuples are encoded to
|
||||
bytestrings using UTF-8
|
||||
"""
|
||||
encoded = []
|
||||
for k, v in params:
|
||||
encoded.append((
|
||||
k.encode('utf-8') if isinstance(k, unicode) else k,
|
||||
v.encode('utf-8') if isinstance(v, unicode) else v))
|
||||
return encoded
|
||||
|
||||
|
||||
def decode_params_utf8(params):
|
||||
"""Ensures that all parameters in a list of 2-element tuples are decoded to
|
||||
unicode using UTF-8.
|
||||
"""
|
||||
decoded = []
|
||||
for k, v in params:
|
||||
decoded.append((
|
||||
k.decode('utf-8') if isinstance(k, str) else k,
|
||||
v.decode('utf-8') if isinstance(v, str) else v))
|
||||
return decoded
|
||||
|
||||
|
||||
urlencoded = set(always_safe) | set(u'=&;%+~')
|
||||
|
||||
|
||||
def urldecode(query):
|
||||
"""Decode a query string in x-www-form-urlencoded format into a sequence
|
||||
of two-element tuples.
|
||||
|
||||
Unlike urlparse.parse_qsl(..., strict_parsing=True) urldecode will enforce
|
||||
correct formatting of the query string by validation. If validation fails
|
||||
a ValueError will be raised. urllib.parse_qsl will only raise errors if
|
||||
any of name-value pairs omits the equals sign.
|
||||
"""
|
||||
# Check if query contains invalid characters
|
||||
if query and not set(query) <= urlencoded:
|
||||
raise ValueError('Invalid characters in query string.')
|
||||
|
||||
# Check for correctly hex encoded values using a regular expression
|
||||
# All encoded values begin with % followed by two hex characters
|
||||
# correct = %00, %A0, %0A, %FF
|
||||
# invalid = %G0, %5H, %PO
|
||||
invalid_hex = u'%[^0-9A-Fa-f]|%[0-9A-Fa-f][^0-9A-Fa-f]'
|
||||
if len(re.findall(invalid_hex, query)):
|
||||
raise ValueError('Invalid hex encoding in query string.')
|
||||
|
||||
query = query.decode('utf-8') if isinstance(query, str) else query
|
||||
# We want to allow queries such as "c2" whereas urlparse.parse_qsl
|
||||
# with the strict_parsing flag will not.
|
||||
params = urlparse.parse_qsl(query, keep_blank_values=True)
|
||||
|
||||
# unicode all the things
|
||||
return decode_params_utf8(params)
|
||||
|
||||
|
||||
def extract_params(raw):
|
||||
"""Extract parameters and return them as a list of 2-tuples.
|
||||
|
||||
Will successfully extract parameters from urlencoded query strings,
|
||||
dicts, or lists of 2-tuples. Empty strings/dicts/lists will return an
|
||||
empty list of parameters. Any other input will result in a return
|
||||
value of None.
|
||||
"""
|
||||
if isinstance(raw, basestring):
|
||||
try:
|
||||
params = urldecode(raw)
|
||||
except ValueError:
|
||||
params = None
|
||||
elif hasattr(raw, '__iter__'):
|
||||
try:
|
||||
dict(raw)
|
||||
except ValueError:
|
||||
params = None
|
||||
except TypeError:
|
||||
params = None
|
||||
else:
|
||||
params = list(raw.items() if isinstance(raw, dict) else raw)
|
||||
params = decode_params_utf8(params)
|
||||
else:
|
||||
params = None
|
||||
|
||||
return params
|
||||
|
||||
|
||||
class Request(object):
|
||||
"""A malleable representation of a signable HTTP request.
|
||||
|
||||
Body argument may contain any data, but parameters will only be decoded if
|
||||
they are one of:
|
||||
|
||||
* urlencoded query string
|
||||
* dict
|
||||
* list of 2-tuples
|
||||
|
||||
Anything else will be treated as raw body data to be passed through
|
||||
unmolested.
|
||||
"""
|
||||
|
||||
def __init__(self, uri, http_method=u'GET', body=None, headers=None):
|
||||
self.uri = uri
|
||||
self.http_method = http_method
|
||||
self.headers = headers or {}
|
||||
self.body = body
|
||||
self.decoded_body = extract_params(body)
|
||||
self.oauth_params = []
|
||||
|
||||
@property
|
||||
def uri_query(self):
|
||||
return urlparse.urlparse(self.uri).query
|
||||
|
||||
@property
|
||||
def uri_query_params(self):
|
||||
return urlparse.parse_qsl(self.uri_query, keep_blank_values=True,
|
||||
strict_parsing=True)
|
||||
@@ -0,0 +1,13 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from __future__ import absolute_import
|
||||
|
||||
"""
|
||||
oauthlib.oauth1
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
This module is a wrapper for the most recent implementation of OAuth 1.0 Client
|
||||
and Server classes.
|
||||
"""
|
||||
|
||||
from .rfc5849 import Client, Server
|
||||
|
||||
@@ -0,0 +1,350 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from __future__ import absolute_import
|
||||
|
||||
"""
|
||||
oauthlib.oauth1.rfc5849
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
This module is an implementation of various logic needed
|
||||
for signing and checking OAuth 1.0 RFC 5849 requests.
|
||||
"""
|
||||
|
||||
import logging
|
||||
import urlparse
|
||||
|
||||
from oauthlib.common import Request, urlencode
|
||||
from . import parameters, signature, utils
|
||||
|
||||
SIGNATURE_HMAC = u"HMAC-SHA1"
|
||||
SIGNATURE_RSA = u"RSA-SHA1"
|
||||
SIGNATURE_PLAINTEXT = u"PLAINTEXT"
|
||||
SIGNATURE_METHODS = (SIGNATURE_HMAC, SIGNATURE_RSA, SIGNATURE_PLAINTEXT)
|
||||
|
||||
SIGNATURE_TYPE_AUTH_HEADER = u'AUTH_HEADER'
|
||||
SIGNATURE_TYPE_QUERY = u'QUERY'
|
||||
SIGNATURE_TYPE_BODY = u'BODY'
|
||||
|
||||
CONTENT_TYPE_FORM_URLENCODED = u'application/x-www-form-urlencoded'
|
||||
|
||||
|
||||
class Client(object):
|
||||
"""A client used to sign OAuth 1.0 RFC 5849 requests"""
|
||||
def __init__(self, client_key,
|
||||
client_secret=None,
|
||||
resource_owner_key=None,
|
||||
resource_owner_secret=None,
|
||||
callback_uri=None,
|
||||
signature_method=SIGNATURE_HMAC,
|
||||
signature_type=SIGNATURE_TYPE_AUTH_HEADER,
|
||||
rsa_key=None, verifier=None):
|
||||
self.client_key = client_key
|
||||
self.client_secret = client_secret
|
||||
self.resource_owner_key = resource_owner_key
|
||||
self.resource_owner_secret = resource_owner_secret
|
||||
self.signature_method = signature_method
|
||||
self.signature_type = signature_type
|
||||
self.callback_uri = callback_uri
|
||||
self.rsa_key = rsa_key
|
||||
self.verifier = verifier
|
||||
|
||||
if self.signature_method == SIGNATURE_RSA and self.rsa_key is None:
|
||||
raise ValueError('rsa_key is required when using RSA signature method.')
|
||||
|
||||
def get_oauth_signature(self, request):
|
||||
"""Get an OAuth signature to be used in signing a request
|
||||
"""
|
||||
if self.signature_method == SIGNATURE_PLAINTEXT:
|
||||
# fast-path
|
||||
return signature.sign_plaintext(self.client_secret,
|
||||
self.resource_owner_secret)
|
||||
|
||||
uri, headers, body = self._render(request)
|
||||
|
||||
collected_params = signature.collect_parameters(
|
||||
uri_query=urlparse.urlparse(uri).query,
|
||||
body=body,
|
||||
headers=headers)
|
||||
logging.debug("Collected params: {0}".format(collected_params))
|
||||
|
||||
normalized_params = signature.normalize_parameters(collected_params)
|
||||
normalized_uri = signature.normalize_base_string_uri(request.uri)
|
||||
logging.debug("Normalized params: {0}".format(normalized_params))
|
||||
logging.debug("Normalized URI: {0}".format(normalized_uri))
|
||||
|
||||
base_string = signature.construct_base_string(request.http_method,
|
||||
normalized_uri, normalized_params)
|
||||
|
||||
logging.debug("Base signing string: {0}".format(base_string))
|
||||
|
||||
if self.signature_method == SIGNATURE_HMAC:
|
||||
sig = signature.sign_hmac_sha1(base_string, self.client_secret,
|
||||
self.resource_owner_secret)
|
||||
elif self.signature_method == SIGNATURE_RSA:
|
||||
sig = signature.sign_rsa_sha1(base_string, self.rsa_key)
|
||||
else:
|
||||
sig = signature.sign_plaintext(self.client_secret,
|
||||
self.resource_owner_secret)
|
||||
|
||||
logging.debug("Signature: {0}".format(sig))
|
||||
return sig
|
||||
|
||||
def get_oauth_params(self):
|
||||
"""Get the basic OAuth parameters to be used in generating a signature.
|
||||
"""
|
||||
params = [
|
||||
(u'oauth_nonce', utils.generate_nonce()),
|
||||
(u'oauth_timestamp', utils.generate_timestamp()),
|
||||
(u'oauth_version', u'1.0'),
|
||||
(u'oauth_signature_method', self.signature_method),
|
||||
(u'oauth_consumer_key', self.client_key),
|
||||
]
|
||||
if self.resource_owner_key:
|
||||
params.append((u'oauth_token', self.resource_owner_key))
|
||||
if self.callback_uri:
|
||||
params.append((u'oauth_callback', self.callback_uri))
|
||||
if self.verifier:
|
||||
params.append((u'oauth_verifier', self.verifier))
|
||||
|
||||
return params
|
||||
|
||||
def _render(self, request, formencode=False):
|
||||
"""Render a signed request according to signature type
|
||||
|
||||
Returns a 3-tuple containing the request URI, headers, and body.
|
||||
|
||||
If the formencode argument is True and the body contains parameters, it
|
||||
is escaped and returned as a valid formencoded string.
|
||||
"""
|
||||
# TODO what if there are body params on a header-type auth?
|
||||
# TODO what if there are query params on a body-type auth?
|
||||
|
||||
uri, headers, body = request.uri, request.headers, request.body
|
||||
|
||||
# TODO: right now these prepare_* methods are very narrow in scope--they
|
||||
# only affect their little thing. In some cases (for example, with
|
||||
# header auth) it might be advantageous to allow these methods to touch
|
||||
# other parts of the request, like the headers—so the prepare_headers
|
||||
# method could also set the Content-Type header to x-www-form-urlencoded
|
||||
# like the spec requires. This would be a fundamental change though, and
|
||||
# I'm not sure how I feel about it.
|
||||
if self.signature_type == SIGNATURE_TYPE_AUTH_HEADER:
|
||||
headers = parameters.prepare_headers(request.oauth_params, request.headers)
|
||||
elif self.signature_type == SIGNATURE_TYPE_BODY and request.decoded_body is not None:
|
||||
body = parameters.prepare_form_encoded_body(request.oauth_params, request.decoded_body)
|
||||
if formencode:
|
||||
body = urlencode(body)
|
||||
headers['Content-Type'] = u'application/x-www-form-urlencoded'
|
||||
elif self.signature_type == SIGNATURE_TYPE_QUERY:
|
||||
uri = parameters.prepare_request_uri_query(request.oauth_params, request.uri)
|
||||
else:
|
||||
raise ValueError('Unknown signature type specified.')
|
||||
|
||||
return uri, headers, body
|
||||
|
||||
def sign(self, uri, http_method=u'GET', body=None, headers=None):
|
||||
"""Sign a request
|
||||
|
||||
Signs an HTTP request with the specified parts.
|
||||
|
||||
Returns a 3-tuple of the signed request's URI, headers, and body.
|
||||
Note that http_method is not returned as it is unaffected by the OAuth
|
||||
signing process.
|
||||
|
||||
The body argument may be a dict, a list of 2-tuples, or a formencoded
|
||||
string. The Content-Type header must be 'application/x-www-form-urlencoded'
|
||||
if it is present.
|
||||
|
||||
If the body argument is not one of the above, it will be returned
|
||||
verbatim as it is unaffected by the OAuth signing process. Attempting to
|
||||
sign a request with non-formencoded data using the OAuth body signature
|
||||
type is invalid and will raise an exception.
|
||||
|
||||
If the body does contain parameters, it will be returned as a properly-
|
||||
formatted formencoded string.
|
||||
|
||||
All string data MUST be unicode. This includes strings inside body
|
||||
dicts, for example.
|
||||
"""
|
||||
# normalize request data
|
||||
request = Request(uri, http_method, body, headers)
|
||||
|
||||
# sanity check
|
||||
content_type = request.headers.get('Content-Type', None)
|
||||
multipart = content_type and content_type.startswith('multipart/')
|
||||
should_have_params = content_type == CONTENT_TYPE_FORM_URLENCODED
|
||||
has_params = request.decoded_body is not None
|
||||
# 3.4.1.3.1. Parameter Sources
|
||||
# [Parameters are collected from the HTTP request entity-body, but only
|
||||
# if [...]:
|
||||
# * The entity-body is single-part.
|
||||
if multipart and has_params:
|
||||
raise ValueError("Headers indicate a multipart body but body contains parameters.")
|
||||
# * The entity-body follows the encoding requirements of the
|
||||
# "application/x-www-form-urlencoded" content-type as defined by
|
||||
# [W3C.REC-html40-19980424].
|
||||
elif should_have_params and not has_params:
|
||||
raise ValueError("Headers indicate a formencoded body but body was not decodable.")
|
||||
# * The HTTP request entity-header includes the "Content-Type"
|
||||
# header field set to "application/x-www-form-urlencoded".
|
||||
elif not should_have_params and has_params:
|
||||
raise ValueError("Body contains parameters but Content-Type header was not set.")
|
||||
|
||||
# 3.5.2. Form-Encoded Body
|
||||
# Protocol parameters can be transmitted in the HTTP request entity-
|
||||
# body, but only if the following REQUIRED conditions are met:
|
||||
# o The entity-body is single-part.
|
||||
# o The entity-body follows the encoding requirements of the
|
||||
# "application/x-www-form-urlencoded" content-type as defined by
|
||||
# [W3C.REC-html40-19980424].
|
||||
# o The HTTP request entity-header includes the "Content-Type" header
|
||||
# field set to "application/x-www-form-urlencoded".
|
||||
elif self.signature_type == SIGNATURE_TYPE_BODY and not (
|
||||
should_have_params and has_params and not multipart):
|
||||
raise ValueError('Body signatures may only be used with form-urlencoded content')
|
||||
|
||||
# generate the basic OAuth parameters
|
||||
request.oauth_params = self.get_oauth_params()
|
||||
|
||||
# generate the signature
|
||||
request.oauth_params.append((u'oauth_signature', self.get_oauth_signature(request)))
|
||||
|
||||
# render the signed request and return it
|
||||
return self._render(request, formencode=True)
|
||||
|
||||
|
||||
class Server(object):
|
||||
"""A server used to verify OAuth 1.0 RFC 5849 requests"""
|
||||
def __init__(self, signature_method=SIGNATURE_HMAC, rsa_key=None):
|
||||
self.signature_method = signature_method
|
||||
self.rsa_key = rsa_key
|
||||
|
||||
def get_client_secret(self, client_key):
|
||||
raise NotImplementedError("Subclasses must implement this function.")
|
||||
|
||||
def get_resource_owner_secret(self, resource_owner_key):
|
||||
raise NotImplementedError("Subclasses must implement this function.")
|
||||
|
||||
def get_signature_type_and_params(self, uri_query, headers, body):
|
||||
signature_types_with_oauth_params = filter(lambda s: s[1], (
|
||||
(SIGNATURE_TYPE_AUTH_HEADER, utils.filter_oauth_params(
|
||||
signature.collect_parameters(headers=headers,
|
||||
exclude_oauth_signature=False))),
|
||||
(SIGNATURE_TYPE_BODY, utils.filter_oauth_params(
|
||||
signature.collect_parameters(body=body,
|
||||
exclude_oauth_signature=False))),
|
||||
(SIGNATURE_TYPE_QUERY, utils.filter_oauth_params(
|
||||
signature.collect_parameters(uri_query=uri_query,
|
||||
exclude_oauth_signature=False))),
|
||||
))
|
||||
|
||||
if len(signature_types_with_oauth_params) > 1:
|
||||
raise ValueError('oauth_ params must come from only 1 signature type but were found in %s' % ', '.join(
|
||||
[s[0] for s in signature_types_with_oauth_params]))
|
||||
try:
|
||||
signature_type, params = signature_types_with_oauth_params[0]
|
||||
except IndexError:
|
||||
raise ValueError('oauth_ params are missing. Could not determine signature type.')
|
||||
|
||||
return signature_type, dict(params)
|
||||
|
||||
def check_client_key(self, client_key):
|
||||
raise NotImplementedError("Subclasses must implement this function.")
|
||||
|
||||
def check_resource_owner_key(self, client_key, resource_owner_key):
|
||||
raise NotImplementedError("Subclasses must implement this function.")
|
||||
|
||||
def check_timestamp_and_nonce(self, timestamp, nonce):
|
||||
raise NotImplementedError("Subclasses must implement this function.")
|
||||
|
||||
def check_request_signature(self, uri, http_method=u'GET', body='',
|
||||
headers=None):
|
||||
"""Check a request's supplied signature to make sure the request is
|
||||
valid.
|
||||
|
||||
Servers should return HTTP status 400 if a ValueError exception
|
||||
is raised and HTTP status 401 on return value False.
|
||||
|
||||
Per `section 3.2`_ of the spec.
|
||||
|
||||
.. _`section 3.2`: http://tools.ietf.org/html/rfc5849#section-3.2
|
||||
"""
|
||||
headers = headers or {}
|
||||
signature_type = None
|
||||
# FIXME: urlparse does not return unicode!
|
||||
uri_query = urlparse.urlparse(uri).query
|
||||
|
||||
signature_type, params = self.get_signature_type_and_params(uri_query,
|
||||
headers, body)
|
||||
|
||||
# the parameters may not include duplicate oauth entries
|
||||
filtered_params = utils.filter_oauth_params(params)
|
||||
if len(filtered_params) != len(params):
|
||||
raise ValueError("Duplicate OAuth entries.")
|
||||
|
||||
params = dict(params)
|
||||
request_signature = params.get(u'oauth_signature')
|
||||
client_key = params.get(u'oauth_consumer_key')
|
||||
resource_owner_key = params.get(u'oauth_token')
|
||||
nonce = params.get(u'oauth_nonce')
|
||||
timestamp = params.get(u'oauth_timestamp')
|
||||
callback_uri = params.get(u'oauth_callback')
|
||||
verifier = params.get(u'oauth_verifier')
|
||||
signature_method = params.get(u'oauth_signature_method')
|
||||
|
||||
# ensure all mandatory parameters are present
|
||||
if not all((request_signature, client_key, nonce,
|
||||
timestamp, signature_method)):
|
||||
raise ValueError("Missing OAuth parameters.")
|
||||
|
||||
# if version is supplied, it must be "1.0"
|
||||
if u'oauth_version' in params and params[u'oauth_version'] != u'1.0':
|
||||
raise ValueError("Invalid OAuth version.")
|
||||
|
||||
# signature method must be valid
|
||||
if not signature_method in SIGNATURE_METHODS:
|
||||
raise ValueError("Invalid signature method.")
|
||||
|
||||
# ensure client key is valid
|
||||
if not self.check_client_key(client_key):
|
||||
return False
|
||||
|
||||
# ensure resource owner key is valid and not expired
|
||||
if not self.check_resource_owner_key(client_key, resource_owner_key):
|
||||
return False
|
||||
|
||||
# ensure the nonce and timestamp haven't been used before
|
||||
if not self.check_timestamp_and_nonce(timestamp, nonce):
|
||||
return False
|
||||
|
||||
# FIXME: extract realm, then self.check_realm
|
||||
|
||||
# oauth_client parameters depend on client chosen signature method
|
||||
# which may vary for each request, section 3.4
|
||||
# HMAC-SHA1 and PLAINTEXT share parameters
|
||||
if signature_method == SIGNATURE_RSA:
|
||||
oauth_client = Client(client_key,
|
||||
resource_owner_key=resource_owner_key,
|
||||
callback_uri=callback_uri,
|
||||
signature_method=signature_method,
|
||||
signature_type=signature_type,
|
||||
rsa_key=self.rsa_key, verifier=verifier)
|
||||
else:
|
||||
client_secret = self.get_client_secret(client_key)
|
||||
resource_owner_secret = self.get_resource_owner_secret(
|
||||
resource_owner_key)
|
||||
oauth_client = Client(client_key,
|
||||
client_secret=client_secret,
|
||||
resource_owner_key=resource_owner_key,
|
||||
resource_owner_secret=resource_owner_secret,
|
||||
callback_uri=callback_uri,
|
||||
signature_method=signature_method,
|
||||
signature_type=signature_type,
|
||||
verifier=verifier)
|
||||
|
||||
request = Request(uri, http_method, body, headers)
|
||||
request.oauth_params = params
|
||||
|
||||
client_signature = oauth_client.get_oauth_signature(request)
|
||||
|
||||
# FIXME: use near constant time string compare to avoid timing attacks
|
||||
return client_signature == request_signature
|
||||
@@ -0,0 +1,134 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from __future__ import absolute_import
|
||||
|
||||
"""
|
||||
oauthlib.parameters
|
||||
~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
This module contains methods related to `section 3.5`_ of the OAuth 1.0a spec.
|
||||
|
||||
.. _`section 3.5`: http://tools.ietf.org/html/rfc5849#section-3.5
|
||||
"""
|
||||
|
||||
from urlparse import urlparse, urlunparse
|
||||
from . import utils
|
||||
from oauthlib.common import extract_params, urlencode
|
||||
|
||||
|
||||
# TODO: do we need filter_params now that oauth_params are handled by Request?
|
||||
# We can easily pass in just oauth protocol params.
|
||||
@utils.filter_params
|
||||
def prepare_headers(oauth_params, headers=None, realm=None):
|
||||
"""**Prepare the Authorization header.**
|
||||
Per `section 3.5.1`_ of the spec.
|
||||
|
||||
Protocol parameters can be transmitted using the HTTP "Authorization"
|
||||
header field as defined by `RFC2617`_ with the auth-scheme name set to
|
||||
"OAuth" (case insensitive).
|
||||
|
||||
For example::
|
||||
|
||||
Authorization: OAuth realm="Example",
|
||||
oauth_consumer_key="0685bd9184jfhq22",
|
||||
oauth_token="ad180jjd733klru7",
|
||||
oauth_signature_method="HMAC-SHA1",
|
||||
oauth_signature="wOJIO9A2W5mFwDgiDvZbTSMK%2FPY%3D",
|
||||
oauth_timestamp="137131200",
|
||||
oauth_nonce="4572616e48616d6d65724c61686176",
|
||||
oauth_version="1.0"
|
||||
|
||||
|
||||
.. _`section 3.5.1`: http://tools.ietf.org/html/rfc5849#section-3.5.1
|
||||
.. _`RFC2617`: http://tools.ietf.org/html/rfc2617
|
||||
"""
|
||||
headers = headers or {}
|
||||
|
||||
# Protocol parameters SHALL be included in the "Authorization" header
|
||||
# field as follows:
|
||||
authorization_header_parameters_parts = []
|
||||
for oauth_parameter_name, value in oauth_params:
|
||||
# 1. Parameter names and values are encoded per Parameter Encoding
|
||||
# (`Section 3.6`_)
|
||||
#
|
||||
# .. _`Section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
escaped_name = utils.escape(oauth_parameter_name)
|
||||
escaped_value = utils.escape(value)
|
||||
|
||||
# 2. Each parameter's name is immediately followed by an "=" character
|
||||
# (ASCII code 61), a """ character (ASCII code 34), the parameter
|
||||
# value (MAY be empty), and another """ character (ASCII code 34).
|
||||
part = u'{0}="{1}"'.format(escaped_name, escaped_value)
|
||||
|
||||
authorization_header_parameters_parts.append(part)
|
||||
|
||||
# 3. Parameters are separated by a "," character (ASCII code 44) and
|
||||
# OPTIONAL linear whitespace per `RFC2617`_.
|
||||
#
|
||||
# .. _`RFC2617`: http://tools.ietf.org/html/rfc2617
|
||||
authorization_header_parameters = ', '.join(
|
||||
authorization_header_parameters_parts)
|
||||
|
||||
# 4. The OPTIONAL "realm" parameter MAY be added and interpreted per
|
||||
# `RFC2617 section 1.2`_.
|
||||
#
|
||||
# .. _`RFC2617 section 1.2`: http://tools.ietf.org/html/rfc2617#section-1.2
|
||||
if realm:
|
||||
# NOTE: realm should *not* be escaped
|
||||
authorization_header_parameters = (u'realm="%s", ' % realm +
|
||||
authorization_header_parameters)
|
||||
|
||||
# the auth-scheme name set to "OAuth" (case insensitive).
|
||||
authorization_header = u'OAuth %s' % authorization_header_parameters
|
||||
|
||||
# contribute the Authorization header to the given headers
|
||||
full_headers = {}
|
||||
full_headers.update(headers)
|
||||
full_headers[u'Authorization'] = authorization_header
|
||||
return full_headers
|
||||
|
||||
|
||||
def _append_params(oauth_params, params):
|
||||
"""Append OAuth params to an existing set of parameters.
|
||||
|
||||
Both params and oauth_params is must be lists of 2-tuples.
|
||||
|
||||
Per `section 3.5.2`_ and `3.5.3`_ of the spec.
|
||||
|
||||
.. _`section 3.5.2`: http://tools.ietf.org/html/rfc5849#section-3.5.2
|
||||
.. _`3.5.3`: http://tools.ietf.org/html/rfc5849#section-3.5.3
|
||||
|
||||
"""
|
||||
merged = list(params)
|
||||
merged.extend(oauth_params)
|
||||
# The request URI / entity-body MAY include other request-specific
|
||||
# parameters, in which case, the protocol parameters SHOULD be appended
|
||||
# following the request-specific parameters, properly separated by an "&"
|
||||
# character (ASCII code 38)
|
||||
merged.sort(key=lambda i: i[0].startswith('oauth_'))
|
||||
return merged
|
||||
|
||||
|
||||
def prepare_form_encoded_body(oauth_params, body):
|
||||
"""Prepare the Form-Encoded Body.
|
||||
|
||||
Per `section 3.5.2`_ of the spec.
|
||||
|
||||
.. _`section 3.5.2`: http://tools.ietf.org/html/rfc5849#section-3.5.2
|
||||
|
||||
"""
|
||||
# append OAuth params to the existing body
|
||||
return _append_params(oauth_params, body)
|
||||
|
||||
|
||||
def prepare_request_uri_query(oauth_params, uri):
|
||||
"""Prepare the Request URI Query.
|
||||
|
||||
Per `section 3.5.3`_ of the spec.
|
||||
|
||||
.. _`section 3.5.3`: http://tools.ietf.org/html/rfc5849#section-3.5.3
|
||||
|
||||
"""
|
||||
# append OAuth params to the existing set of query components
|
||||
sch, net, path, par, query, fra = urlparse(uri)
|
||||
query = urlencode(_append_params(oauth_params, extract_params(query) or []))
|
||||
return urlunparse((sch, net, path, par, query, fra))
|
||||
@@ -0,0 +1,501 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from __future__ import absolute_import
|
||||
"""
|
||||
oauthlib.oauth1.rfc5849.signature
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
This module represents a direct implementation of `section 3.4`_ of the spec.
|
||||
|
||||
Terminology:
|
||||
* Client: software interfacing with an OAuth API
|
||||
* Server: the API provider
|
||||
* Resource Owner: the user who is granting authorization to the client
|
||||
|
||||
Steps for signing a request:
|
||||
|
||||
1. Collect parameters from the uri query, auth header, & body
|
||||
2. Normalize those parameters
|
||||
3. Normalize the uri
|
||||
4. Pass the normalized uri, normalized parameters, and http method to
|
||||
construct the base string
|
||||
5. Pass the base string and any keys needed to a signing function
|
||||
|
||||
.. _`section 3.4`: http://tools.ietf.org/html/rfc5849#section-3.4
|
||||
"""
|
||||
import binascii
|
||||
import hashlib
|
||||
import hmac
|
||||
import urlparse
|
||||
from . import utils
|
||||
from oauthlib.common import extract_params
|
||||
|
||||
|
||||
def construct_base_string(http_method, base_string_uri,
|
||||
normalized_encoded_request_parameters):
|
||||
"""**String Construction**
|
||||
Per `section 3.4.1.1`_ of the spec.
|
||||
|
||||
For example, the HTTP request::
|
||||
|
||||
POST /request?b5=%3D%253D&a3=a&c%40=&a2=r%20b HTTP/1.1
|
||||
Host: example.com
|
||||
Content-Type: application/x-www-form-urlencoded
|
||||
Authorization: OAuth realm="Example",
|
||||
oauth_consumer_key="9djdj82h48djs9d2",
|
||||
oauth_token="kkk9d7dh3k39sjv7",
|
||||
oauth_signature_method="HMAC-SHA1",
|
||||
oauth_timestamp="137131201",
|
||||
oauth_nonce="7d8f3e4a",
|
||||
oauth_signature="bYT5CMsGcbgUdFHObYMEfcx6bsw%3D"
|
||||
|
||||
c2&a3=2+q
|
||||
|
||||
is represented by the following signature base string (line breaks
|
||||
are for display purposes only)::
|
||||
|
||||
POST&http%3A%2F%2Fexample.com%2Frequest&a2%3Dr%2520b%26a3%3D2%2520q
|
||||
%26a3%3Da%26b5%3D%253D%25253D%26c%2540%3D%26c2%3D%26oauth_consumer_
|
||||
key%3D9djdj82h48djs9d2%26oauth_nonce%3D7d8f3e4a%26oauth_signature_m
|
||||
ethod%3DHMAC-SHA1%26oauth_timestamp%3D137131201%26oauth_token%3Dkkk
|
||||
9d7dh3k39sjv7
|
||||
|
||||
.. _`section 3.4.1.1`: http://tools.ietf.org/html/rfc5849#section-3.4.1.1
|
||||
"""
|
||||
|
||||
# The signature base string is constructed by concatenating together,
|
||||
# in order, the following HTTP request elements:
|
||||
|
||||
# 1. The HTTP request method in uppercase. For example: "HEAD",
|
||||
# "GET", "POST", etc. If the request uses a custom HTTP method, it
|
||||
# MUST be encoded (`Section 3.6`_).
|
||||
#
|
||||
# .. _`Section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
base_string = utils.escape(http_method.upper())
|
||||
|
||||
# 2. An "&" character (ASCII code 38).
|
||||
base_string += u'&'
|
||||
|
||||
# 3. The base string URI from `Section 3.4.1.2`_, after being encoded
|
||||
# (`Section 3.6`_).
|
||||
#
|
||||
# .. _`Section 3.4.1.2`: http://tools.ietf.org/html/rfc5849#section-3.4.1.2
|
||||
# .. _`Section 3.4.6`: http://tools.ietf.org/html/rfc5849#section-3.4.6
|
||||
base_string += utils.escape(base_string_uri)
|
||||
|
||||
# 4. An "&" character (ASCII code 38).
|
||||
base_string += u'&'
|
||||
|
||||
# 5. The request parameters as normalized in `Section 3.4.1.3.2`_, after
|
||||
# being encoded (`Section 3.6`).
|
||||
#
|
||||
# .. _`Section 3.4.1.3.2`: http://tools.ietf.org/html/rfc5849#section-3.4.1.3.2
|
||||
# .. _`Section 3.4.6`: http://tools.ietf.org/html/rfc5849#section-3.4.6
|
||||
base_string += utils.escape(normalized_encoded_request_parameters)
|
||||
|
||||
return base_string
|
||||
|
||||
|
||||
def normalize_base_string_uri(uri):
|
||||
"""**Base String URI**
|
||||
Per `section 3.4.1.2`_ of the spec.
|
||||
|
||||
For example, the HTTP request::
|
||||
|
||||
GET /r%20v/X?id=123 HTTP/1.1
|
||||
Host: EXAMPLE.COM:80
|
||||
|
||||
is represented by the base string URI: "http://example.com/r%20v/X".
|
||||
|
||||
In another example, the HTTPS request::
|
||||
|
||||
GET /?q=1 HTTP/1.1
|
||||
Host: www.example.net:8080
|
||||
|
||||
is represented by the base string URI: "https://www.example.net:8080/".
|
||||
|
||||
.. _`section 3.4.1.2`: http://tools.ietf.org/html/rfc5849#section-3.4.1.2
|
||||
"""
|
||||
if not isinstance(uri, unicode):
|
||||
raise ValueError('uri must be a unicode object.')
|
||||
|
||||
# FIXME: urlparse does not support unicode
|
||||
scheme, netloc, path, params, query, fragment = urlparse.urlparse(uri)
|
||||
|
||||
# The scheme, authority, and path of the request resource URI `RFC3986`
|
||||
# are included by constructing an "http" or "https" URI representing
|
||||
# the request resource (without the query or fragment) as follows:
|
||||
#
|
||||
# .. _`RFC2616`: http://tools.ietf.org/html/rfc3986
|
||||
|
||||
# 1. The scheme and host MUST be in lowercase.
|
||||
scheme = scheme.lower()
|
||||
netloc = netloc.lower()
|
||||
|
||||
# 2. The host and port values MUST match the content of the HTTP
|
||||
# request "Host" header field.
|
||||
# TODO: enforce this constraint
|
||||
|
||||
# 3. The port MUST be included if it is not the default port for the
|
||||
# scheme, and MUST be excluded if it is the default. Specifically,
|
||||
# the port MUST be excluded when making an HTTP request `RFC2616`_
|
||||
# to port 80 or when making an HTTPS request `RFC2818`_ to port 443.
|
||||
# All other non-default port numbers MUST be included.
|
||||
#
|
||||
# .. _`RFC2616`: http://tools.ietf.org/html/rfc2616
|
||||
# .. _`RFC2818`: http://tools.ietf.org/html/rfc2818
|
||||
default_ports = (
|
||||
(u'http', u'80'),
|
||||
(u'https', u'443'),
|
||||
)
|
||||
if u':' in netloc:
|
||||
host, port = netloc.split(u':', 1)
|
||||
if (scheme, port) in default_ports:
|
||||
netloc = host
|
||||
|
||||
return urlparse.urlunparse((scheme, netloc, path, u'', u'', u''))
|
||||
|
||||
|
||||
# ** Request Parameters **
|
||||
#
|
||||
# Per `section 3.4.1.3`_ of the spec.
|
||||
#
|
||||
# In order to guarantee a consistent and reproducible representation of
|
||||
# the request parameters, the parameters are collected and decoded to
|
||||
# their original decoded form. They are then sorted and encoded in a
|
||||
# particular manner that is often different from their original
|
||||
# encoding scheme, and concatenated into a single string.
|
||||
#
|
||||
# .. _`section 3.4.1.3`: http://tools.ietf.org/html/rfc5849#section-3.4.1.3
|
||||
|
||||
def collect_parameters(uri_query='', body=[], headers=None,
|
||||
exclude_oauth_signature=True):
|
||||
"""**Parameter Sources**
|
||||
|
||||
Parameters starting with `oauth_` will be unescaped.
|
||||
|
||||
Body parameters must be supplied as a dict, a list of 2-tuples, or a
|
||||
formencoded query string.
|
||||
|
||||
Headers must be supplied as a dict.
|
||||
|
||||
Per `section 3.4.1.3.1`_ of the spec.
|
||||
|
||||
For example, the HTTP request::
|
||||
|
||||
POST /request?b5=%3D%253D&a3=a&c%40=&a2=r%20b HTTP/1.1
|
||||
Host: example.com
|
||||
Content-Type: application/x-www-form-urlencoded
|
||||
Authorization: OAuth realm="Example",
|
||||
oauth_consumer_key="9djdj82h48djs9d2",
|
||||
oauth_token="kkk9d7dh3k39sjv7",
|
||||
oauth_signature_method="HMAC-SHA1",
|
||||
oauth_timestamp="137131201",
|
||||
oauth_nonce="7d8f3e4a",
|
||||
oauth_signature="djosJKDKJSD8743243%2Fjdk33klY%3D"
|
||||
|
||||
c2&a3=2+q
|
||||
|
||||
contains the following (fully decoded) parameters used in the
|
||||
signature base sting::
|
||||
|
||||
+------------------------+------------------+
|
||||
| Name | Value |
|
||||
+------------------------+------------------+
|
||||
| b5 | =%3D |
|
||||
| a3 | a |
|
||||
| c@ | |
|
||||
| a2 | r b |
|
||||
| oauth_consumer_key | 9djdj82h48djs9d2 |
|
||||
| oauth_token | kkk9d7dh3k39sjv7 |
|
||||
| oauth_signature_method | HMAC-SHA1 |
|
||||
| oauth_timestamp | 137131201 |
|
||||
| oauth_nonce | 7d8f3e4a |
|
||||
| c2 | |
|
||||
| a3 | 2 q |
|
||||
+------------------------+------------------+
|
||||
|
||||
Note that the value of "b5" is "=%3D" and not "==". Both "c@" and
|
||||
"c2" have empty values. While the encoding rules specified in this
|
||||
specification for the purpose of constructing the signature base
|
||||
string exclude the use of a "+" character (ASCII code 43) to
|
||||
represent an encoded space character (ASCII code 32), this practice
|
||||
is widely used in "application/x-www-form-urlencoded" encoded values,
|
||||
and MUST be properly decoded, as demonstrated by one of the "a3"
|
||||
parameter instances (the "a3" parameter is used twice in this
|
||||
request).
|
||||
|
||||
.. _`section 3.4.1.3.1`: http://tools.ietf.org/html/rfc5849#section-3.4.1.3.1
|
||||
"""
|
||||
headers = headers or {}
|
||||
params = []
|
||||
|
||||
# The parameters from the following sources are collected into a single
|
||||
# list of name/value pairs:
|
||||
|
||||
# * The query component of the HTTP request URI as defined by
|
||||
# `RFC3986, Section 3.4`_. The query component is parsed into a list
|
||||
# of name/value pairs by treating it as an
|
||||
# "application/x-www-form-urlencoded" string, separating the names
|
||||
# and values and decoding them as defined by
|
||||
# `W3C.REC-html40-19980424`_, Section 17.13.4.
|
||||
#
|
||||
# .. _`RFC3986, Section 3.4`: http://tools.ietf.org/html/rfc3986#section-3.4
|
||||
# .. _`W3C.REC-html40-19980424`: http://tools.ietf.org/html/rfc5849#ref-W3C.REC-html40-19980424
|
||||
if uri_query:
|
||||
params.extend(urlparse.parse_qsl(uri_query, keep_blank_values=True))
|
||||
|
||||
# * The OAuth HTTP "Authorization" header field (`Section 3.5.1`_) if
|
||||
# present. The header's content is parsed into a list of name/value
|
||||
# pairs excluding the "realm" parameter if present. The parameter
|
||||
# values are decoded as defined by `Section 3.5.1`_.
|
||||
#
|
||||
# .. _`Section 3.5.1`: http://tools.ietf.org/html/rfc5849#section-3.5.1
|
||||
if headers:
|
||||
headers_lower = dict((k.lower(), v) for k, v in headers.items())
|
||||
authorization_header = headers_lower.get(u'authorization')
|
||||
if authorization_header is not None:
|
||||
params.extend([i for i in utils.parse_authorization_header(
|
||||
authorization_header) if i[0] != u'realm'])
|
||||
|
||||
# * The HTTP request entity-body, but only if all of the following
|
||||
# conditions are met:
|
||||
# * The entity-body is single-part.
|
||||
#
|
||||
# * The entity-body follows the encoding requirements of the
|
||||
# "application/x-www-form-urlencoded" content-type as defined by
|
||||
# `W3C.REC-html40-19980424`_.
|
||||
|
||||
# * The HTTP request entity-header includes the "Content-Type"
|
||||
# header field set to "application/x-www-form-urlencoded".
|
||||
#
|
||||
# .._`W3C.REC-html40-19980424`: http://tools.ietf.org/html/rfc5849#ref-W3C.REC-html40-19980424
|
||||
|
||||
# TODO: enforce header param inclusion conditions
|
||||
bodyparams = extract_params(body) or []
|
||||
params.extend(bodyparams)
|
||||
|
||||
# ensure all oauth params are unescaped
|
||||
unescaped_params = []
|
||||
for k, v in params:
|
||||
if k.startswith(u'oauth_'):
|
||||
v = utils.unescape(v)
|
||||
unescaped_params.append((k, v))
|
||||
|
||||
# The "oauth_signature" parameter MUST be excluded from the signature
|
||||
# base string if present.
|
||||
if exclude_oauth_signature:
|
||||
unescaped_params = filter(lambda i: i[0] != u'oauth_signature',
|
||||
unescaped_params)
|
||||
|
||||
return unescaped_params
|
||||
|
||||
|
||||
def normalize_parameters(params):
|
||||
"""**Parameters Normalization**
|
||||
Per `section 3.4.1.3.2`_ of the spec.
|
||||
|
||||
For example, the list of parameters from the previous section would
|
||||
be normalized as follows:
|
||||
|
||||
Encoded::
|
||||
|
||||
+------------------------+------------------+
|
||||
| Name | Value |
|
||||
+------------------------+------------------+
|
||||
| b5 | %3D%253D |
|
||||
| a3 | a |
|
||||
| c%40 | |
|
||||
| a2 | r%20b |
|
||||
| oauth_consumer_key | 9djdj82h48djs9d2 |
|
||||
| oauth_token | kkk9d7dh3k39sjv7 |
|
||||
| oauth_signature_method | HMAC-SHA1 |
|
||||
| oauth_timestamp | 137131201 |
|
||||
| oauth_nonce | 7d8f3e4a |
|
||||
| c2 | |
|
||||
| a3 | 2%20q |
|
||||
+------------------------+------------------+
|
||||
|
||||
Sorted::
|
||||
|
||||
+------------------------+------------------+
|
||||
| Name | Value |
|
||||
+------------------------+------------------+
|
||||
| a2 | r%20b |
|
||||
| a3 | 2%20q |
|
||||
| a3 | a |
|
||||
| b5 | %3D%253D |
|
||||
| c%40 | |
|
||||
| c2 | |
|
||||
| oauth_consumer_key | 9djdj82h48djs9d2 |
|
||||
| oauth_nonce | 7d8f3e4a |
|
||||
| oauth_signature_method | HMAC-SHA1 |
|
||||
| oauth_timestamp | 137131201 |
|
||||
| oauth_token | kkk9d7dh3k39sjv7 |
|
||||
+------------------------+------------------+
|
||||
|
||||
Concatenated Pairs::
|
||||
|
||||
+-------------------------------------+
|
||||
| Name=Value |
|
||||
+-------------------------------------+
|
||||
| a2=r%20b |
|
||||
| a3=2%20q |
|
||||
| a3=a |
|
||||
| b5=%3D%253D |
|
||||
| c%40= |
|
||||
| c2= |
|
||||
| oauth_consumer_key=9djdj82h48djs9d2 |
|
||||
| oauth_nonce=7d8f3e4a |
|
||||
| oauth_signature_method=HMAC-SHA1 |
|
||||
| oauth_timestamp=137131201 |
|
||||
| oauth_token=kkk9d7dh3k39sjv7 |
|
||||
+-------------------------------------+
|
||||
|
||||
and concatenated together into a single string (line breaks are for
|
||||
display purposes only)::
|
||||
|
||||
a2=r%20b&a3=2%20q&a3=a&b5=%3D%253D&c%40=&c2=&oauth_consumer_key=9dj
|
||||
dj82h48djs9d2&oauth_nonce=7d8f3e4a&oauth_signature_method=HMAC-SHA1
|
||||
&oauth_timestamp=137131201&oauth_token=kkk9d7dh3k39sjv7
|
||||
|
||||
.. _`section 3.4.1.3.2`: http://tools.ietf.org/html/rfc5849#section-3.4.1.3.2
|
||||
"""
|
||||
|
||||
# The parameters collected in `Section 3.4.1.3`_ are normalized into a
|
||||
# single string as follows:
|
||||
#
|
||||
# .. _`Section 3.4.1.3`: http://tools.ietf.org/html/rfc5849#section-3.4.1.3
|
||||
|
||||
# 1. First, the name and value of each parameter are encoded
|
||||
# (`Section 3.6`_).
|
||||
#
|
||||
# .. _`Section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
key_values = [(utils.escape(k), utils.escape(v)) for k, v in params]
|
||||
|
||||
# 2. The parameters are sorted by name, using ascending byte value
|
||||
# ordering. If two or more parameters share the same name, they
|
||||
# are sorted by their value.
|
||||
key_values.sort()
|
||||
|
||||
# 3. The name of each parameter is concatenated to its corresponding
|
||||
# value using an "=" character (ASCII code 61) as a separator, even
|
||||
# if the value is empty.
|
||||
parameter_parts = [u'{0}={1}'.format(k, v) for k, v in key_values]
|
||||
|
||||
# 4. The sorted name/value pairs are concatenated together into a
|
||||
# single string by using an "&" character (ASCII code 38) as
|
||||
# separator.
|
||||
return u'&'.join(parameter_parts)
|
||||
|
||||
|
||||
def sign_hmac_sha1(base_string, client_secret, resource_owner_secret):
|
||||
"""**HMAC-SHA1**
|
||||
|
||||
The "HMAC-SHA1" signature method uses the HMAC-SHA1 signature
|
||||
algorithm as defined in `RFC2104`_::
|
||||
|
||||
digest = HMAC-SHA1 (key, text)
|
||||
|
||||
Per `section 3.4.2`_ of the spec.
|
||||
|
||||
.. _`RFC2104`: http://tools.ietf.org/html/rfc2104
|
||||
.. _`section 3.4.2`: http://tools.ietf.org/html/rfc5849#section-3.4.2
|
||||
"""
|
||||
|
||||
# The HMAC-SHA1 function variables are used in following way:
|
||||
|
||||
# text is set to the value of the signature base string from
|
||||
# `Section 3.4.1.1`_.
|
||||
#
|
||||
# .. _`Section 3.4.1.1`: http://tools.ietf.org/html/rfc5849#section-3.4.1.1
|
||||
text = base_string
|
||||
|
||||
# key is set to the concatenated values of:
|
||||
# 1. The client shared-secret, after being encoded (`Section 3.6`_).
|
||||
#
|
||||
# .. _`Section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
key = utils.escape(client_secret or u'')
|
||||
|
||||
# 2. An "&" character (ASCII code 38), which MUST be included
|
||||
# even when either secret is empty.
|
||||
key += u'&'
|
||||
|
||||
# 3. The token shared-secret, after being encoded (`Section 3.6`_).
|
||||
#
|
||||
# .. _`Section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
key += utils.escape(resource_owner_secret or u'')
|
||||
|
||||
# FIXME: HMAC does not support unicode!
|
||||
key_utf8 = key.encode('utf-8')
|
||||
text_utf8 = text.encode('utf-8')
|
||||
signature = hmac.new(key_utf8, text_utf8, hashlib.sha1)
|
||||
|
||||
# digest is used to set the value of the "oauth_signature" protocol
|
||||
# parameter, after the result octet string is base64-encoded
|
||||
# per `RFC2045, Section 6.8`.
|
||||
#
|
||||
# .. _`RFC2045, Section 6.8`: http://tools.ietf.org/html/rfc2045#section-6.8
|
||||
return binascii.b2a_base64(signature.digest())[:-1].decode('utf-8')
|
||||
|
||||
|
||||
def sign_rsa_sha1(base_string, rsa_private_key):
|
||||
"""**RSA-SHA1**
|
||||
|
||||
Per `section 3.4.3`_ of the spec.
|
||||
|
||||
The "RSA-SHA1" signature method uses the RSASSA-PKCS1-v1_5 signature
|
||||
algorithm as defined in `RFC3447, Section 8.2`_ (also known as
|
||||
PKCS#1), using SHA-1 as the hash function for EMSA-PKCS1-v1_5. To
|
||||
use this method, the client MUST have established client credentials
|
||||
with the server that included its RSA public key (in a manner that is
|
||||
beyond the scope of this specification).
|
||||
|
||||
NOTE: this method requires the python-rsa library.
|
||||
|
||||
.. _`section 3.4.3`: http://tools.ietf.org/html/rfc5849#section-3.4.3
|
||||
.. _`RFC3447, Section 8.2`: http://tools.ietf.org/html/rfc3447#section-8.2
|
||||
|
||||
"""
|
||||
|
||||
# TODO: finish RSA documentation
|
||||
|
||||
import rsa
|
||||
key = rsa.PrivateKey.load_pkcs1(rsa_private_key)
|
||||
sig = rsa.sign(base_string, key, 'SHA-1')
|
||||
return binascii.b2a_base64(sig)[:-1]
|
||||
|
||||
|
||||
def sign_plaintext(client_secret, resource_owner_secret):
|
||||
"""Sign a request using plaintext.
|
||||
|
||||
Per `section 3.4.4`_ of the spec.
|
||||
|
||||
The "PLAINTEXT" method does not employ a signature algorithm. It
|
||||
MUST be used with a transport-layer mechanism such as TLS or SSL (or
|
||||
sent over a secure channel with equivalent protections). It does not
|
||||
utilize the signature base string or the "oauth_timestamp" and
|
||||
"oauth_nonce" parameters.
|
||||
|
||||
.. _`section 3.4.4`: http://tools.ietf.org/html/rfc5849#section-3.4.4
|
||||
|
||||
"""
|
||||
|
||||
# The "oauth_signature" protocol parameter is set to the concatenated
|
||||
# value of:
|
||||
|
||||
# 1. The client shared-secret, after being encoded (`Section 3.6`_).
|
||||
#
|
||||
# .. _`Section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
signature = utils.escape(client_secret or u'')
|
||||
|
||||
# 2. An "&" character (ASCII code 38), which MUST be included even
|
||||
# when either secret is empty.
|
||||
signature += u'&'
|
||||
|
||||
# 3. The token shared-secret, after being encoded (`Section 3.6`_).
|
||||
#
|
||||
# .. _`Section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
signature += utils.escape(resource_owner_secret or u'')
|
||||
|
||||
return signature
|
||||
|
||||
@@ -0,0 +1,141 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
|
||||
"""
|
||||
oauthlib.utils
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
This module contains utility methods used by various parts of the OAuth
|
||||
spec.
|
||||
"""
|
||||
|
||||
import string
|
||||
import time
|
||||
import urllib2
|
||||
from random import getrandbits, choice
|
||||
|
||||
from oauthlib.common import quote, unquote
|
||||
|
||||
UNICODE_ASCII_CHARACTER_SET = (string.ascii_letters.decode('ascii') +
|
||||
string.digits.decode('ascii'))
|
||||
|
||||
|
||||
def filter_params(target):
|
||||
"""Decorator which filters params to remove non-oauth_* parameters
|
||||
|
||||
Assumes the decorated method takes a params dict or list of tuples as its
|
||||
first argument.
|
||||
"""
|
||||
def wrapper(params, *args, **kwargs):
|
||||
params = filter_oauth_params(params)
|
||||
return target(params, *args, **kwargs)
|
||||
|
||||
wrapper.__doc__ = target.__doc__
|
||||
return wrapper
|
||||
|
||||
|
||||
def filter_oauth_params(params):
|
||||
"""Removes all non oauth parameters from a dict or a list of params."""
|
||||
is_oauth = lambda kv: kv[0].startswith(u"oauth_")
|
||||
if isinstance(params, dict):
|
||||
return filter(is_oauth, params.items())
|
||||
else:
|
||||
return filter(is_oauth, params)
|
||||
|
||||
|
||||
def generate_timestamp():
|
||||
"""Get seconds since epoch (UTC).
|
||||
|
||||
Per `section 3.3`_ of the spec.
|
||||
|
||||
.. _`section 3.3`: http://tools.ietf.org/html/rfc5849#section-3.3
|
||||
"""
|
||||
return unicode(int(time.time()))
|
||||
|
||||
|
||||
def generate_nonce():
|
||||
"""Generate pseudorandom nonce that is unlikely to repeat.
|
||||
|
||||
Per `section 3.3`_ of the spec.
|
||||
|
||||
A random 64-bit number is appended to the epoch timestamp for both
|
||||
randomness and to decrease the likelihood of collisions.
|
||||
|
||||
.. _`section 3.3`: http://tools.ietf.org/html/rfc5849#section-3.3
|
||||
"""
|
||||
return unicode(getrandbits(64)) + generate_timestamp()
|
||||
|
||||
|
||||
def generate_token(length=20, chars=UNICODE_ASCII_CHARACTER_SET):
|
||||
"""Generates a generic OAuth token
|
||||
|
||||
According to `section 2`_ of the spec, the method of token
|
||||
construction is undefined. This implementation is simply a random selection
|
||||
of `length` choices from `chars`.
|
||||
|
||||
Credit to Ignacio Vazquez-Abrams for his excellent `Stackoverflow answer`_
|
||||
|
||||
.. _`Stackoverflow answer` : http://stackoverflow.com/questions/2257441/
|
||||
python-random-string-generation-with-upper-case-letters-and-digits
|
||||
|
||||
"""
|
||||
return u''.join(choice(chars) for x in range(length))
|
||||
|
||||
|
||||
def escape(u):
|
||||
"""Escape a unicode string in an OAuth-compatible fashion.
|
||||
|
||||
Per `section 3.6`_ of the spec.
|
||||
|
||||
.. _`section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
|
||||
"""
|
||||
if not isinstance(u, unicode):
|
||||
raise ValueError('Only unicode objects are escapable.')
|
||||
# Letters, digits, and the characters '_.-' are already treated as safe
|
||||
# by urllib.quote(). We need to add '~' to fully support rfc5849.
|
||||
return quote(u, safe='~')
|
||||
|
||||
|
||||
def unescape(u):
|
||||
if not isinstance(u, unicode):
|
||||
raise ValueError('Only unicode objects are unescapable.')
|
||||
return unquote(u)
|
||||
|
||||
|
||||
def urlencode(query):
|
||||
"""Encode a sequence of two-element tuples or dictionary into a URL query string.
|
||||
|
||||
Operates using an OAuth-safe escape() method, in contrast to urllib.urlencode.
|
||||
"""
|
||||
# Convert dictionaries to list of tuples
|
||||
if isinstance(query, dict):
|
||||
query = query.items()
|
||||
return u"&".join([u'='.join([escape(k), escape(v)]) for k, v in query])
|
||||
|
||||
|
||||
def parse_keqv_list(l):
|
||||
"""A unicode-safe version of urllib2.parse_keqv_list"""
|
||||
encoded_list = [u.encode('utf-8') for u in l]
|
||||
encoded_parsed = urllib2.parse_keqv_list(encoded_list)
|
||||
return dict((k.decode('utf-8'),
|
||||
v.decode('utf-8')) for k,v in encoded_parsed.items())
|
||||
|
||||
|
||||
def parse_http_list(u):
|
||||
"""A unicode-safe version of urllib2.parse_http_list"""
|
||||
encoded_str = u.encode('utf-8')
|
||||
encoded_list = urllib2.parse_http_list(encoded_str)
|
||||
return [s.decode('utf-8') for s in encoded_list]
|
||||
|
||||
|
||||
def parse_authorization_header(authorization_header):
|
||||
"""Parse an OAuth authorization header into a list of 2-tuples"""
|
||||
auth_scheme = u'OAuth '
|
||||
if authorization_header.startswith(auth_scheme):
|
||||
authorization_header = authorization_header.replace(auth_scheme, u'', 1)
|
||||
items = parse_http_list(authorization_header)
|
||||
try:
|
||||
return parse_keqv_list(items).items()
|
||||
except ValueError:
|
||||
raise ValueError('Malformed authorization header')
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from __future__ import absolute_import
|
||||
|
||||
"""
|
||||
oauthlib.oauth2
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
This module is a wrapper for the most recent implementation of OAuth 2.0 Client
|
||||
and Server classes.
|
||||
"""
|
||||
|
||||
from .draft25 import Client, Server
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
"""
|
||||
oauthlib.oauth2.draft_25
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
This module is an implementation of various logic needed
|
||||
for signing and checking OAuth 2.0 draft 25 requests.
|
||||
"""
|
||||
|
||||
class Client(object):
|
||||
pass
|
||||
|
||||
class Server(object):
|
||||
pass
|
||||
|
||||
@@ -0,0 +1,131 @@
|
||||
from __future__ import absolute_import
|
||||
"""
|
||||
oauthlib.oauth2.draft25.tokens
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
This module contains methods for adding two types of access tokens to requests.
|
||||
|
||||
- Bearer http://tools.ietf.org/html/draft-ietf-oauth-saml2-bearer-08
|
||||
- MAC http://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-00
|
||||
|
||||
"""
|
||||
from binascii import b2a_base64
|
||||
import hashlib
|
||||
import hmac
|
||||
from urlparse import urlparse
|
||||
|
||||
from . import utils
|
||||
|
||||
|
||||
def prepare_mac_header(token, uri, key, http_method, nonce=None, headers=None,
|
||||
body=None, ext=u'', hash_algorithm=u'hmac-sha-1'):
|
||||
"""Add an `MAC Access Authentication`_ signature to headers.
|
||||
|
||||
Unlike OAuth 1, this HMAC signature does not require inclusion of the request
|
||||
payload/body, neither does it use a combination of client_secret and
|
||||
token_secret but rather a mac_key provided together with the access token.
|
||||
|
||||
Currently two algorithms are supported, "hmac-sha-1" and "hmac-sha-256",
|
||||
`extension algorithms`_ are not supported.
|
||||
|
||||
Example MAC Authorization header, linebreaks added for clarity
|
||||
|
||||
Authorization: MAC id="h480djs93hd8",
|
||||
nonce="1336363200:dj83hs9s",
|
||||
mac="bhCQXTVyfj5cmA9uKkPFx1zeOXM="
|
||||
|
||||
.. _`MAC Access Authentication`: http://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01
|
||||
.. _`extension algorithms`: http://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01#section-7.1
|
||||
|
||||
:param uri: Request URI.
|
||||
:param headers: Request headers as a dictionary.
|
||||
:param http_method: HTTP Request method.
|
||||
:param key: MAC given provided by token endpoint.
|
||||
:param algorithm: HMAC algorithm provided by token endpoint.
|
||||
:return: headers dictionary with the authorization field added.
|
||||
"""
|
||||
http_method = http_method.upper()
|
||||
host, port = utils.host_from_uri(uri)
|
||||
|
||||
if hash_algorithm.lower() == u'hmac-sha-1':
|
||||
h = hashlib.sha1
|
||||
else:
|
||||
h = hashlib.sha256
|
||||
|
||||
nonce = nonce or u'{0}:{1}'.format(utils.generate_nonce(), utils.generate_timestamp())
|
||||
sch, net, path, par, query, fra = urlparse(uri)
|
||||
|
||||
if query:
|
||||
request_uri = path + u'?' + query
|
||||
else:
|
||||
request_uri = path
|
||||
|
||||
# Hash the body/payload
|
||||
if body is not None:
|
||||
bodyhash = b2a_base64(h(body).digest())[:-1].decode('utf-8')
|
||||
else:
|
||||
bodyhash = u''
|
||||
|
||||
# Create the normalized base string
|
||||
base = []
|
||||
base.append(nonce)
|
||||
base.append(http_method.upper())
|
||||
base.append(request_uri)
|
||||
base.append(host)
|
||||
base.append(port)
|
||||
base.append(bodyhash)
|
||||
base.append(ext)
|
||||
base_string = '\n'.join(base) + u'\n'
|
||||
|
||||
# hmac struggles with unicode strings - http://bugs.python.org/issue5285
|
||||
if isinstance(key, unicode):
|
||||
key = key.encode('utf-8')
|
||||
sign = hmac.new(key, base_string, h)
|
||||
sign = b2a_base64(sign.digest())[:-1].decode('utf-8')
|
||||
|
||||
header = []
|
||||
header.append(u'MAC id="%s"' % token)
|
||||
header.append(u'nonce="%s"' % nonce)
|
||||
if bodyhash:
|
||||
header.append(u'bodyhash="%s"' % bodyhash)
|
||||
if ext:
|
||||
header.append(u'ext="%s"' % ext)
|
||||
header.append(u'mac="%s"' % sign)
|
||||
|
||||
headers = headers or {}
|
||||
headers[u'Authorization'] = u', '.join(header)
|
||||
return headers
|
||||
|
||||
|
||||
def prepare_bearer_uri(token, uri):
|
||||
"""Add a `Bearer Token`_ to the request URI.
|
||||
Not recommended, use only if client can't use authorization header or body.
|
||||
|
||||
http://www.example.com/path?access_token=h480djs93hd8
|
||||
|
||||
.. _`Bearer Token`: http://tools.ietf.org/html/draft-ietf-oauth-v2-bearer-18
|
||||
"""
|
||||
return utils.add_params_to_uri(uri, [((u'access_token', token))])
|
||||
|
||||
|
||||
def prepare_bearer_headers(token, headers=None):
|
||||
"""Add a `Bearer Token`_ to the request URI.
|
||||
Recommended method of passing bearer tokens.
|
||||
|
||||
Authorization: Bearer h480djs93hd8
|
||||
|
||||
.. _`Bearer Token`: http://tools.ietf.org/html/draft-ietf-oauth-v2-bearer-18
|
||||
"""
|
||||
headers = headers or {}
|
||||
headers[u'Authorization'] = u'Bearer %s' % token
|
||||
return headers
|
||||
|
||||
|
||||
def prepare_bearer_body(token, body=u''):
|
||||
"""Add a `Bearer Token`_ to the request body.
|
||||
|
||||
access_token=h480djs93hd8
|
||||
|
||||
.. _`Bearer Token`: http://tools.ietf.org/html/draft-ietf-oauth-v2-bearer-18
|
||||
"""
|
||||
return utils.add_params_to_qs(body, [((u'access_token', token))])
|
||||
@@ -0,0 +1,128 @@
|
||||
"""
|
||||
oauthlib.utils
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
This module contains utility methods used by various parts of the OAuth 2 spec.
|
||||
"""
|
||||
|
||||
import random
|
||||
import string
|
||||
import time
|
||||
import urllib
|
||||
from urlparse import urlparse, urlunparse, parse_qsl
|
||||
|
||||
UNICODE_ASCII_CHARACTER_SET = (string.ascii_letters.decode('ascii') +
|
||||
string.digits.decode('ascii'))
|
||||
|
||||
def add_params_to_qs(query, params):
|
||||
"""Extend a query with a list of two-tuples.
|
||||
|
||||
:param query: Query string.
|
||||
:param params: List of two-tuples.
|
||||
:return: extended query
|
||||
"""
|
||||
queryparams = parse_qsl(query, keep_blank_values=True)
|
||||
queryparams.extend(params)
|
||||
return urlencode(queryparams)
|
||||
|
||||
|
||||
def add_params_to_uri(uri, params):
|
||||
"""Add a list of two-tuples to the uri query components.
|
||||
|
||||
:param uri: Full URI.
|
||||
:param params: List of two-tuples.
|
||||
:return: uri with extended query
|
||||
"""
|
||||
sch, net, path, par, query, fra = urlparse(uri)
|
||||
query = add_params_to_qs(query, params)
|
||||
return urlunparse((sch, net, path, par, query, fra))
|
||||
|
||||
|
||||
def escape(u):
|
||||
"""Escape a string in an OAuth-compatible fashion.
|
||||
|
||||
Per `section 3.6`_ of the spec.
|
||||
|
||||
.. _`section 3.6`: http://tools.ietf.org/html/rfc5849#section-3.6
|
||||
|
||||
"""
|
||||
if not isinstance(u, unicode):
|
||||
raise ValueError('Only unicode objects are escapable.')
|
||||
return urllib.quote(u.encode('utf-8'), safe='~')
|
||||
|
||||
|
||||
def generate_nonce():
|
||||
"""Generate pseudorandom nonce that is unlikely to repeat.
|
||||
|
||||
Per `section 3.2.1`_ of the MAC Access Authentication spec.
|
||||
|
||||
A random 64-bit number is appended to the epoch timestamp for both
|
||||
randomness and to decrease the likelihood of collisions.
|
||||
|
||||
.. _`section 3.2.1`: http://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01#section-3.2.1
|
||||
"""
|
||||
return unicode(unicode(random.getrandbits(64)) + generate_timestamp())
|
||||
|
||||
|
||||
def generate_timestamp():
|
||||
"""Get seconds since epoch (UTC).
|
||||
|
||||
Per `section 3.2.1`_ of the MAC Access Authentication spec.
|
||||
|
||||
.. _`section 3.2.1`: http://tools.ietf.org/html/draft-ietf-oauth-v2-http-mac-01#section-3.2.1
|
||||
"""
|
||||
return unicode(int(time.time()))
|
||||
|
||||
|
||||
def generate_token(length=20, chars=UNICODE_ASCII_CHARACTER_SET):
|
||||
"""Generates a generic OAuth 2 token
|
||||
|
||||
According to `section 1.4`_ and `section 1.5` of the spec, the method of token
|
||||
construction is undefined. This implementation is simply a random selection
|
||||
of `length` choices from `chars`. SystemRandom is used since it provides
|
||||
higher entropy than random.choice.
|
||||
|
||||
.. _`section 1.4`: http://tools.ietf.org/html/draft-ietf-oauth-v2-25#section-1.4
|
||||
.. _`section 1.5`: http://tools.ietf.org/html/draft-ietf-oauth-v2-25#section-1.5
|
||||
"""
|
||||
rand = random.SystemRandom()
|
||||
return u''.join(rand.choice(chars) for x in range(length))
|
||||
|
||||
|
||||
def host_from_uri(uri):
|
||||
"""Extract hostname and port from URI.
|
||||
|
||||
Will use default port for HTTP and HTTPS if none is present in the URI.
|
||||
|
||||
>>> host_from_uri(u'https://www.example.com/path?query')
|
||||
u'www.example.com', u'443'
|
||||
>>> host_from_uri(u'http://www.example.com:8080/path?query')
|
||||
u'www.example.com', u'8080'
|
||||
|
||||
:param uri: Full URI.
|
||||
:param http_method: HTTP request method.
|
||||
:return: hostname, port
|
||||
"""
|
||||
default_ports = {
|
||||
u'HTTP' : u'80',
|
||||
u'HTTPS' : u'443',
|
||||
}
|
||||
|
||||
sch, netloc, path, par, query, fra = urlparse(uri)
|
||||
if u':' in netloc:
|
||||
netloc, port = netloc.split(u':', 1)
|
||||
else:
|
||||
port = default_ports.get(sch.upper())
|
||||
|
||||
return netloc, port
|
||||
|
||||
|
||||
def urlencode(query):
|
||||
"""Encode a sequence of two-element tuples or dictionary into a URL query string.
|
||||
|
||||
Operates using an OAuth-safe escape() method, in contrast to urllib.urlenocde.
|
||||
"""
|
||||
# Convert dictionaries to list of tuples
|
||||
if isinstance(query, dict):
|
||||
query = query.items()
|
||||
return "&".join(['='.join([escape(k), escape(v)]) for k, v in query])
|
||||
Reference in New Issue
Block a user