Ë
    ùmxiv  ã                   óô  — d Z ddlZddlmZ ddlZddlZddlmZ ddlm	Z	 ddlm
Z
 ddlmZ ddlmZ ddlmZ ej                  ej                   ej"                  ej$                  hZd	gZ eed
«      r ej,                  «       Zn$ ej0                  dd«      j3                  «       dk(  Zerde
j4                  › �Znde
j4                  › �Zde› d�Zedz   Zedz   Zedz   Zedz   Z  G d„ dejB                  «      Z!y)zÇTools for using the Google `Cloud Identity and Access Management (IAM)
API`_'s auth-related functionality.

.. _Cloud Identity and Access Management (IAM) API:
    https://cloud.google.com/iam/docs/
é    N)Ú_exponential_backoff)Ú_helpers)Úcredentials)Úcrypt)Ú
exceptions)Úmtlsz#https://www.googleapis.com/auth/iamÚshould_use_client_certÚ!GOOGLE_API_USE_CLIENT_CERTIFICATEÚfalseÚtrueziamcredentials.mtls.ziamcredentials.zhttps://z!/v1/projects/-/serviceAccounts/{}z:generateAccessTokenz	:signBlobz:signJwtz:generateIdTokenc                   óp   — e Zd ZdZd„ Zd„ Zed„ «       Z ej                  e
j                  «      d„ «       Zy)ÚSignera  Signs messages using the IAM `signBlob API`_.

    This is useful when you need to sign bytes but do not have access to the
    credential's private key file.

    .. _signBlob API:
        https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts
        /signBlob
    c                 ó.   — || _         || _        || _        y)aÝ  
        Args:
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            credentials (google.auth.credentials.Credentials): The credentials
                that will be used to authenticate the request to the IAM API.
                The credentials must have of one the following scopes:

                - https://www.googleapis.com/auth/iam
                - https://www.googleapis.com/auth/cloud-platform
            service_account_email (str): The service account email identifying
                which service account to use to sign bytes. Often, this can
                be the same as the service account email in the given
                credentials.
        N)Ú_requestÚ_credentialsÚ_service_account_email)ÚselfÚrequestr   Úservice_account_emails       úF/home/htdocs/ttos/venv/lib/python3.12/site-packages/google/auth/iam.pyÚ__init__zSigner.__init__S   s   € ð   ˆŒØ'ˆÔØ&;ˆÕ#ó    c                 ó^  — t        j                  |«      }d}t        j                  t        j
                  | j                  j                  «      j                  | j                  «      }ddi}t        j                  dt        j                  |«      j                  d«      i«      j                  d«      }t!        j"                  «       }|D ]Ì  }| j                  j%                  | j&                  |||«       | j'                  ||||¬«      }|j(                  t*        v rŒS|j(                  t,        j.                  k7  r.t1        j2                  dj                  |j4                  «      «      ‚t        j6                  |j4                  j                  d«      «      c S  t1        j2                  d«      ‚)	z(Makes a request to the API signBlob API.ÚPOSTzContent-Typezapplication/jsonÚpayloadzutf-8)ÚurlÚmethodÚbodyÚheadersz&Error calling the IAM signBlob API: {}z#exhausted signBlob endpoint retries)r   Úto_bytesÚ_IAM_SIGN_ENDPOINTÚreplacer   ÚDEFAULT_UNIVERSE_DOMAINr   Úuniverse_domainÚformatr   ÚjsonÚdumpsÚbase64Ú	b64encodeÚdecodeÚencoder   ÚExponentialBackoffÚbefore_requestr   ÚstatusÚIAM_RETRY_CODESÚhttp_clientÚOKr   ÚTransportErrorÚdataÚloads)	r   Úmessager   r   r   r   ÚretriesÚ_Úresponses	            r   Ú_make_signing_requestzSigner._make_signing_requestg   sb  € ä×#Ñ# GÓ,ˆàˆÜ ×(Ñ(Ü×/Ñ/°×1BÑ1B×1RÑ1Ró
ç
‰&�×,Ñ,Ó
-ð 	ð "Ð#5Ð6ˆÜ�z‰zØœ×(Ñ(¨Ó1×8Ñ8¸ÓAÐBó
ç
‰&�‹/ð 	ô '×9Ñ9Ó;ˆØò 	=ˆAØ×Ñ×,Ñ,¨T¯]©]¸FÀCÈÔQà—}‘}¨°VÀ$ÐPW�}ÓXˆHà�‰¤/Ñ1Øà�‰¤+§.¡.Ò0Ü ×/Ñ/Ø<×CÑCÀHÇMÁMÓRóð ô —:‘:˜hŸm™m×2Ñ2°7Ó;Ó<Ò<ð	=ô ×'Ñ'Ð(MÓNÐNr   c                  ó   — y)zÏOptional[str]: The key ID used to identify this private key.

        .. warning::
           This is always ``None``. The key ID used by IAM can not
           be reliably determined ahead of time.
        N© )r   s    r   Úkey_idzSigner.key_id…   s   € ð r   c                 óT   — | j                  |«      }t        j                  |d   «      S )NÚ
signedBlob)r9   r(   Ú	b64decode)r   r5   r8   s      r   ÚsignzSigner.sign�   s(   € à×-Ñ-¨gÓ6ˆÜ×Ñ ¨Ñ 6Ó7Ð7r   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r9   Úpropertyr<   r   Úcopy_docstringr   r   r@   r;   r   r   r   r   H   sK   „ ñò<ò(Oð< ñó ðð €X×Ñ˜UŸ\™\Ó*ñ8ó +ñ8r   r   )"rD   r(   Úhttp.clientÚclientr0   r&   ÚosÚgoogle.authr   r   r   r   r   Úgoogle.auth.transportr   ÚINTERNAL_SERVER_ERRORÚBAD_GATEWAYÚSERVICE_UNAVAILABLEÚGATEWAY_TIMEOUTr/   Ú
_IAM_SCOPEÚhasattrr	   Úuse_client_certÚgetenvÚlowerr#   Ú_IAM_DOMAINÚ_IAM_BASE_URLÚ_IAM_ENDPOINTr!   Ú_IAM_SIGNJWT_ENDPOINTÚ_IAM_IDTOKEN_ENDPOINTr   r;   r   r   ú<module>rZ      s!  ðñó Ý !Û Û 	å ,Ý  Ý #Ý Ý "Ý &ð ×%Ñ%Ø×ÑØ×#Ñ#Ø×Ñð	€ð 4Ð4€
ñ ˆ4Ð)Ô*Ø1�d×1Ñ1Ó3�Oð 	ˆ�	‰	Ð5°wÓ?×EÑEÓGÈ6ÑQð ñ à(¨×)LÑ)LÐ(MÐN�Kà# K×$GÑ$GÐ#HÐI€Kð ˜;˜-Ð'JÐK€ð Ð 6Ñ6€Ø" [Ñ0Ð Ø%¨
Ñ2Ð Ø%Ð(:Ñ:Ð ôJ8ˆU�\‰\õ J8r   