o
    ýÞhk  ã                   @   sÌ   d Z ddlmZ ddlZddlmZ ddlmZ ddlmZ ddl	m
Z
 ddl	mZ dd	lmZ dd
lmZ ddlZddlmZ ddlmZ dZe ¡ Ze ¡ ZG dd„ dejƒZG dd„ dejejƒZdS )zIECDSA (ES256) verifier and signer that use the ``cryptography`` library.
é    )ÚutilsN)Úbackends)Úhashes)Úserialization)Úec)Úpadding)Údecode_dss_signature)Úencode_dss_signature)Ú_helpers)Úbases   -----BEGIN CERTIFICATE-----c                   @   s8   e Zd ZdZdd„ Ze ej¡dd„ ƒZ	e
dd„ ƒZdS )	ÚES256VerifierzãVerifies ECDSA cryptographic signatures using public keys.

    Args:
        public_key (
                cryptography.hazmat.primitives.asymmetric.ec.ECDSAPublicKey):
            The public key used to verify signatures.
    c                 C   s
   || _ d S ©N)Ú_pubkey)ÚselfÚ
public_key© r   úW/var/www/html/premium_crap/venv/lib/python3.10/site-packages/google/auth/crypt/es256.pyÚ__init__/   s   
zES256Verifier.__init__c              	   C   sÔ   t  |¡}t|ƒdkrdS t  ¡ rtj|d d… dd�n
tj|d d… dd�}t  ¡ r6tj|dd … dd�n
tj|dd … dd�}t||ƒ}t  |¡}z| j	 
||t t ¡ ¡¡ W dS  ttjjfyi   Y dS w )Né@   Fé    Úbig©Ú	byteorderT)r
   Úto_bytesÚlenÚis_python_3ÚintÚ
from_bytesr   Úint_from_bytesr	   r   Úverifyr   ÚECDSAr   ÚSHA256Ú
ValueErrorÚcryptographyÚ
exceptionsÚInvalidSignature)r   ÚmessageÚ	signatureÚ	sig_bytesÚrÚsÚasn1_sigr   r   r   r   2   s&   
ÿýÿý

ÿzES256Verifier.verifyc                 C   sD   t  |¡}t|v rtj |t¡}| ¡ }| |ƒS t 	|t¡}| |ƒS )ay  Construct an Verifier instance from a public key or public
        certificate string.

        Args:
            public_key (Union[str, bytes]): The public key in PEM format or the
                x509 public key certificate.

        Returns:
            Verifier: The constructed verifier.

        Raises:
            ValueError: If the public key can't be parsed.
        )
r
   r   Ú_CERTIFICATE_MARKERr#   Úx509Úload_pem_x509_certificateÚ_BACKENDr   r   Úload_pem_public_key)Úclsr   Úpublic_key_dataÚcertÚpubkeyr   r   r   Úfrom_stringK   s   
ÿþzES256Verifier.from_stringN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r
   Úcopy_docstringr   ÚVerifierr   Úclassmethodr5   r   r   r   r   r   &   s    

r   c                   @   sd   e Zd ZdZddd„Zee ej	¡dd„ ƒƒZ
e ej	¡dd„ ƒZedd	d
„ƒZdd„ Zdd„ ZdS )ÚES256Signeraˆ  Signs messages with an ECDSA private key.

    Args:
        private_key (
                cryptography.hazmat.primitives.asymmetric.ec.ECDSAPrivateKey):
            The private key to sign with.
        key_id (str): Optional key ID used to identify this private key. This
            can be useful to associate the private key with its associated
            public key or certificate.
    Nc                 C   s   || _ || _d S r   )Ú_keyÚ_key_id)r   Úprivate_keyÚkey_idr   r   r   r   t   s   
zES256Signer.__init__c                 C   s   | j S r   )r?   )r   r   r   r   rA   x   s   zES256Signer.key_idc                 C   sj   t  |¡}| j |t t ¡ ¡¡}t|ƒ\}}t  	¡ r)|jddd�|jddd� S t
 |d¡t
 |d¡ S )Nr   r   r   )r
   r   r>   Úsignr   r    r   r!   r   r   r   Úint_to_bytes)r   r&   Úasn1_signaturer)   r*   r   r   r   rB   }   s   
ÿÿýzES256Signer.signc                 C   s&   t  |¡}tj|dtd�}| ||d�S )al  Construct a RSASigner from a private key in PEM format.

        Args:
            key (Union[bytes, str]): Private key in PEM format.
            key_id (str): An optional key id used to identify the private key.

        Returns:
            google.auth.crypt._cryptography_rsa.RSASigner: The
            constructed signer.

        Raises:
            ValueError: If ``key`` is not ``bytes`` or ``str`` (unicode).
            UnicodeDecodeError: If ``key`` is ``bytes`` but cannot be decoded
                into a UTF-8 ``str``.
            ValueError: If ``cryptography`` "Could not deserialize key data."
        N)ÚpasswordÚbackend)rA   )r
   r   r   Úload_pem_private_keyr/   )r1   ÚkeyrA   r@   r   r   r   r5   Š   s
   
ÿzES256Signer.from_stringc                 C   s0   | j  ¡ }| jjtjjtjjt 	¡ d�|d< |S )z1Pickle helper that serializes the _key attribute.)ÚencodingÚformatÚencryption_algorithmr>   )
Ú__dict__Úcopyr>   Úprivate_bytesr   ÚEncodingÚPEMÚPrivateFormatÚPKCS8ÚNoEncryption©r   Ústater   r   r   Ú__getstate__¢   s   

ýzES256Signer.__getstate__c                 C   s$   t  |d d¡|d< | j |¡ dS )z3Pickle helper that deserializes the _key attribute.r>   N)r   rG   rL   ÚupdaterT   r   r   r   Ú__setstate__¬   s   zES256Signer.__setstate__r   )r6   r7   r8   r9   r   Úpropertyr
   r:   r   ÚSignerrA   rB   r<   r5   rV   rX   r   r   r   r   r=   h   s    




r=   )r9   r#   r   Úcryptography.exceptionsÚcryptography.hazmatr   Úcryptography.hazmat.primitivesr   r   Ú)cryptography.hazmat.primitives.asymmetricr   r   Ú/cryptography.hazmat.primitives.asymmetric.utilsr   r	   Úcryptography.x509Úgoogle.authr
   Úgoogle.auth.cryptr   r,   Údefault_backendr/   ÚPKCS1v15Ú_PADDINGr;   r   rZ   ÚFromServiceAccountMixinr=   r   r   r   r   Ú<module>   s$   B