Ë
    ùmxi/%  ã                   ó  — d Z ddlZddlZddlZddlZddlZddlZddlmZm	Z	 ddl
mZ ddl
mZ  ej                  e«      ZdZddgZd	Zd
ZdZdZdZ eeeez  z
  ez  «      Zegez  egez  z   Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Z d„ Z!y)z'Helpers for Agent Identity credentials.é    N)ÚquoteÚurlparse)Úenvironment_vars)Ú
exceptionsz‰The cryptography library is required for certificate-based authentication.Please install it with `pip install google-auth[cryptography]`.z+^agents\.global\.org-\d+\.system\.id\.goog$z,^agents\.global\.proj-\d+\.system\.id\.goog$z=/var/run/secrets/workload-spiffe-credentials/certificates.pemé2   gš™™™™™¹?g      à?é   c                 ó�   — | xrC t         j                  j                  | «      xr" t         j                  j                  | «      dkD  S )z)Checks if a file exists and is not empty.r   )ÚosÚpathÚexistsÚgetsize)r   s    úX/home/htdocs/ttos/venv/lib/python3.12/site-packages/google/auth/_agent_identity_utils.pyÚ_is_certificate_file_readyr   <   s1   € àÒF”B—G‘G—N‘N 4Ó(ÒF¬R¯W©W¯_©_¸TÓ-BÀQÑ-FÐFó    c                  ó´  — ddl } t        j                  j                  t        j
                  «      }|syd}t        D ]Ÿ  }	 t        |d«      5 }| j                  |«      }|j                  di «      j                  di «      j                  d«      }t        |«      r|cddd«       c S 	 ddd«       t        t         «      rt         c S t#        j$                  |«       Œ¡ t'        j(                  d
t        j*                  › d�«      ‚# 1 sw Y   Œ^xY w# t        t        t        f$ r1 |s,t        j                  d|t        j
                  t        «       d	}Y Œ¥w xY w)a/  Gets the certificate path from the certificate config file.

    The path to the certificate config file is read from the
    GOOGLE_API_CERTIFICATE_CONFIG environment variable. This function
    implements a retry mechanism to handle cases where the environment
    variable is set before the files are available on the filesystem.

    Returns:
        str: The path to the leaf certificate file.

    Raises:
        google.auth.exceptions.RefreshError: If the certificate config file
            or the certificate file cannot be found after retries.
    r   NFÚrÚcert_configsÚworkloadÚ	cert_pathzfCertificate config file not found at %s (from %s environment variable). Retrying for up to %s seconds.TzšCertificate config or certificate file not found after multiple retries. Token binding protection is failing. You can turn off this protection by setting z) to false to fall back to unbound tokens.)Újsonr
   ÚenvironÚgetr   ÚGOOGLE_API_CERTIFICATE_CONFIGÚ_POLLING_INTERVALSÚopenÚloadr   ÚIOErrorÚ
ValueErrorÚKeyErrorÚ_LOGGERÚwarningÚ_TOTAL_TIMEOUTÚ_WELL_KNOWN_CERT_PATHÚtimeÚsleepr   ÚRefreshErrorÚ7GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES)r   Úcert_config_pathÚhas_logged_warningÚintervalÚfÚcert_configr   s          r   Ú#get_agent_identity_certificate_pathr-   A   sO  € ó ä—z‘z—~‘~Ô&6×&TÑ&TÓUÐÙØàÐä&ò  ˆð	ÜÐ&¨Ó,ð %°Ø"Ÿi™i¨›l�à—O‘O N°BÓ7ß‘S˜ RÓ(ß‘S˜Ó%ð ô
 .¨iÔ8Ø$÷%ó %ð 9÷%ô, &Ô&;Ô<Ü(Ò(ô 	�
‰
�8ÕðA ôD ×
!Ñ
!ð	\ä×SÑSÐ
Tð U*ð	*óð ÷A%ð %ûô œ¤XÐ.ò 
	Ù%Ü—‘ð@à$Ü$×BÑBÜ"ôð &*Ð"Ùð
	ús2   ÁDÁADÂ	DÂ)DÄD	ÄDÄAEÅEc                  ó,  — t         j                  j                  t        j                  d«      j                  «       dk(  } | ryt        «       }|syt        |d«      5 }|j                  «       }ddd«       t        |«      S # 1 sw Y   t        «      S xY w)a1  Gets and parses the agent identity certificate if not opted out.

    Checks if the user has opted out of certificate-bound tokens. If not,
    it gets the certificate path, reads the file, and parses it.

    Returns:
        The parsed certificate object if found and not opted out, otherwise None.
    ÚtrueÚfalseNÚrb)
r
   r   r   r   r'   Úlowerr-   r   ÚreadÚparse_certificate)Úis_opted_outr   Ú	cert_fileÚ
cert_bytess       r   Ú(get_and_parse_agent_identity_certificater8   ‚   sŽ   € ô 	�
‰
�‰Ü×TÑTØó	
÷ ‰%‹'Øñ		ð ñ Øä3Ó5€IÙØä	ˆi˜Ó	ð & )Ø—^‘^Ó%ˆ
÷&ô ˜ZÓ(Ð(÷&ô ˜ZÓ(Ð(ús   ÁB Â Bc                 ót   — 	 ddl m} |j                  | «      S # t        $ r}t        t        «      |‚d}~ww xY w)zÄParses a PEM-encoded certificate.

    Args:
        cert_bytes (bytes): The PEM-encoded certificate bytes.

    Returns:
        cryptography.x509.Certificate: The parsed certificate object.
    r   ©Úx509N)Úcryptographyr;   Úload_pem_x509_certificateÚImportErrorÚCRYPTOGRAPHY_NOT_FOUND_ERROR)r7   r;   Úes      r   r4   r4   ¡   s9   € ð?Ý%à×-Ñ-¨jÓ9Ð9øÜò ?ÜÔ6Ó7¸QÐ>ûð?ús   ‚ ™	7¢2²7c                 óÄ  — 	 ddl m} ddlm} 	 | j                  j                  |j                  «      }|j                  j                  |j                  «      }|D ]M  }t        |«      }|j                  dk(  sŒ|j                  }t        D ]  }t        j                   ||«      sŒ  y ŒO y# |j                  $ r Y yw xY w# t"        $ r}	t#        t$        «      |	‚d}	~	ww xY w)aš  Checks if a certificate is an Agent Identity certificate.

    This is determined by checking the Subject Alternative Name (SAN) for a
    SPIFFE ID with a trust domain matching Agent Identity patterns.

    Args:
        cert (cryptography.x509.Certificate): The parsed certificate object.

    Returns:
        bool: True if the certificate is an Agent Identity certificate,
            False otherwise.
    r   r:   )ÚExtensionOIDFÚspiffeTN)r<   r;   Úcryptography.x509.oidrB   Ú
extensionsÚget_extension_for_oidÚSUBJECT_ALTERNATIVE_NAMEÚExtensionNotFoundÚvalueÚget_values_for_typeÚUniformResourceIdentifierr   ÚschemeÚnetlocÚ,_AGENT_IDENTITY_SPIFFE_TRUST_DOMAIN_PATTERNSÚreÚmatchr>   r?   )
Úcertr;   rB   ÚextÚurisÚuriÚ
parsed_uriÚtrust_domainÚpatternr@   s
             r   Ú_is_agent_identity_certificaterX   ²   sÚ   € ð?Ý%Ý6ð	Ø—/‘/×7Ñ7Ø×5Ñ5óˆCð
 �y‰y×,Ñ,¨T×-KÑ-KÓLˆàò 	$ˆCÜ! #›ˆJØ× Ñ  HÓ,Ø)×0Ñ0�ÜKò $�GÜ—x‘x ¨Õ6Ú#ñ$ð		$ð øð ×%Ñ%ò 	Ùð	ûô ò ?ÜÔ6Ó7¸QÐ>ûð?úsL   ‚C �%B, ´AC Á9+C Â%C Â(C Â,B>Â;C Â=B>Â>C Ã	CÃ
CÃCc                 ób  — 	 ddl m} | j                  |j                  j                  «      }t        j                  |«      j                  «       }t        j                  |«      j                  d«      }|j                  d«      }t        |«      S # t        $ r}t        t        «      |‚d}~ww xY w)a  Calculates the URL-encoded, unpadded, base64-encoded SHA256 hash of a
    DER-encoded certificate.

    Args:
        cert (cryptography.x509.Certificate): The parsed certificate object.

    Returns:
        str: The URL-encoded, unpadded, base64-encoded SHA256 fingerprint.
    r   )Úserializationzutf-8ú=N)Úcryptography.hazmat.primitivesrZ   Úpublic_bytesÚEncodingÚDERÚhashlibÚsha256ÚdigestÚbase64Ú	b64encodeÚdecodeÚrstripr   r>   r?   )rQ   rZ   Úder_certÚfingerprintÚbase64_fingerprintÚunpadded_base64_fingerprintr@   s          r   Ú!calculate_certificate_fingerprintrk   ×   s–   € ð?Ý@à×$Ñ$ ]×%;Ñ%;×%?Ñ%?Ó@ˆÜ—n‘n XÓ.×5Ñ5Ó7ˆô $×-Ñ-¨kÓ:×AÑAÀ'ÓJÐØ&8×&?Ñ&?ÀÓ&DÐ#ÜÐ0Ó1Ð1øÜò ?ÜÔ6Ó7¸QÐ>ûð?ús   ‚BB Â	B.ÂB)Â)B.c                 ó¢   — t        | «      }t        j                  j                  t        j
                  d«      j                  «       dk(  }|xr |S )a‡  Determines if a bound token should be requested.

    This is based on the GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES
    environment variable and whether the certificate is an agent identity cert.

    Args:
        cert (cryptography.x509.Certificate): The parsed certificate object.

    Returns:
        bool: True if a bound token should be requested, False otherwise.
    r/   )rX   r
   r   r   r   r'   r2   )rQ   Úis_agent_certÚis_opted_ins      r   Úshould_request_bound_tokenro   ò   sM   € ô 3°4Ó8€Mä
�
‰
�‰Ü×TÑTØó	
÷ ‰%‹'Øñ		ð ð Ò(˜[Ð(r   c                 óL   — | rt        | «      }t        |«      }|S t        d«      ‚)z2Returns the fingerprint of the cached certificate.z"mTLS connection is not configured.)r4   rk   r   )Úcached_certÚcert_objÚcached_cert_fingerprints      r   Úget_cached_cert_fingerprintrt   	  s0   € áÜ$ [Ó1ˆÜ"CÀHÓ"MÐð #Ð"ô Ð=Ó>Ð>r   )"Ú__doc__rc   r`   Úloggingr
   rO   r$   Úurllib.parser   r   Úgoogle.authr   r   Ú	getLoggerÚ__name__r    r?   rN   r#   Ú_FAST_POLL_CYCLESÚ_FAST_POLL_INTERVALÚ_SLOW_POLL_INTERVALr"   ÚintÚ_SLOW_POLL_CYCLESr   r   r-   r8   r4   rX   rk   ro   rt   © r   r   ú<module>r�      så   ðñ .ã Û Û Û 	Û 	Û ß (å (Ý "ð ˆ'×
Ñ
˜HÓ
%€ðFð ð 3Ø3ð0Ð ,ð
 XÐ ð Ð ØÐ ØÐ Ø€ñ ØÐ(Ð+>Ñ>Ñ?ÐCVÑVóÐ ð +Ð+Ð.?Ñ?ØÐÐ-Ñ-ñÐ ò
Gò
>òB)ò>?ò""?òJ?ò6)ó.#r   