o
    ýÞhB  ã                   @   sœ   d Z ddlZddlmZ ddlZddlmZ ddlmZ ddlm	Z	 ddlm
Z
 ddlmZ ejejejejhZdgZd	Zd
ZdZdZG dd„ de
jƒZdS )zÇTools for using the Google `Cloud Identity and Access Management (IAM)
API`_'s auth-related functionality.

.. _Cloud Identity and Access Management (IAM) API:
    https://cloud.google.com/iam/docs/
é    N)Ú_exponential_backoff)Ú_helpers)Úcredentials)Úcrypt)Ú
exceptionsz#https://www.googleapis.com/auth/iamzZhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:generateAccessTokenzOhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:signBlobzNhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:signJwtzVhttps://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:generateIdTokenc                   @   s@   e Zd ZdZdd„ Zdd„ Zedd„ ƒZe 	e
j¡dd	„ ƒZd
S )ÚSignera  Signs messages using the IAM `signBlob API`_.

    This is useful when you need to sign bytes but do not have access to the
    credential's private key file.

    .. _signBlob API:
        https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts
        /signBlob
    c                 C   s   || _ || _|| _dS )aÝ  
        Args:
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            credentials (google.auth.credentials.Credentials): The credentials
                that will be used to authenticate the request to the IAM API.
                The credentials must have of one the following scopes:

                - https://www.googleapis.com/auth/iam
                - https://www.googleapis.com/auth/cloud-platform
            service_account_email (str): The service account email identifying
                which service account to use to sign bytes. Often, this can
                be the same as the service account email in the given
                credentials.
        N)Ú_requestÚ_credentialsÚ_service_account_email)ÚselfÚrequestr   Úservice_account_email© r   úO/var/www/html/premium_crap/venv/lib/python3.10/site-packages/google/auth/iam.pyÚ__init__I   s   
zSigner.__init__c           	      C   sÐ   t  |¡}d}t tj| jj¡ | j	¡}ddi}t
 dt |¡ d¡i¡ d¡}t ¡ }|D ]4}| j | j|||¡ | j||||d�}|jtv rIq.|jtjkrXt d |j¡¡‚t
 |j d¡¡  S t d¡‚)	z(Makes a request to the API signBlob API.ÚPOSTzContent-Typezapplication/jsonÚpayloadzutf-8)ÚurlÚmethodÚbodyÚheadersz&Error calling the IAM signBlob API: {}z#exhausted signBlob endpoint retries)r   Úto_bytesÚ_IAM_SIGN_ENDPOINTÚreplacer   ÚDEFAULT_UNIVERSE_DOMAINr	   Úuniverse_domainÚformatr
   ÚjsonÚdumpsÚbase64Ú	b64encodeÚdecodeÚencoder   ÚExponentialBackoffÚbefore_requestr   ÚstatusÚIAM_RETRY_CODESÚhttp_clientÚOKr   ÚTransportErrorÚdataÚloads)	r   Úmessager   r   r   r   ÚretriesÚ_Úresponser   r   r   Ú_make_signing_request]   s2   

ÿþÿþ

ÿ
zSigner._make_signing_requestc                 C   s   dS )zÏOptional[str]: The key ID used to identify this private key.

        .. warning::
           This is always ``None``. The key ID used by IAM can not
           be reliably determined ahead of time.
        Nr   )r   r   r   r   Úkey_id{   s   zSigner.key_idc                 C   s   |   |¡}t |d ¡S )NÚ
signedBlob)r0   r   Ú	b64decode)r   r,   r/   r   r   r   Úsign…   s   
zSigner.signN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r0   Úpropertyr1   r   Úcopy_docstringr   r   r4   r   r   r   r   r   >   s    


	r   )r8   r   Úhttp.clientÚclientr'   r   Úgoogle.authr   r   r   r   r   ÚINTERNAL_SERVER_ERRORÚBAD_GATEWAYÚSERVICE_UNAVAILABLEÚGATEWAY_TIMEOUTr&   Ú
_IAM_SCOPEÚ_IAM_ENDPOINTr   Ú_IAM_SIGNJWT_ENDPOINTÚ_IAM_IDTOKEN_ENDPOINTr   r   r   r   r   Ú<module>   s0   üÿÿÿÿ