o
    Þ­j&  ã                   @   s¤   d Z ddlZddlmZ ddlmZ ddlmZ ddlm	Z	 ddl
ZddlmZ ddlmZ d	Ze ¡ Ze	 ¡ Ze ¡ ZG d
d„ dejƒZG dd„ dejejƒZdS )zÐRSA verifier and signer that use the ``cryptography`` library.

This is a much faster implementation than the default (in
``google.auth.crypt._python_rsa``), which depends on the pure-Python
``rsa`` library.
é    N)Úbackends)Úhashes)Úserialization)Úpadding)Ú_helpers)Úbases   -----BEGIN CERTIFICATE-----c                   @   s8   e Zd ZdZdd„ Ze ej¡dd„ ƒZ	e
dd„ ƒZdS )	ÚRSAVerifierzàVerifies RSA cryptographic signatures using public keys.

    Args:
        public_key (
                cryptography.hazmat.primitives.asymmetric.rsa.RSAPublicKey):
            The public key used to verify signatures.
    c                 C   s
   || _ d S ©N)Ú_pubkey)ÚselfÚ
public_key© r   ú`/var/www/html/CropPilot/venv/lib/python3.10/site-packages/google/auth/crypt/_cryptography_rsa.pyÚ__init__/   s   
zRSAVerifier.__init__c              	   C   s@   t  |¡}z| j ||tt¡ W dS  ttjj	fy   Y dS w )NTF)
r   Úto_bytesr
   ÚverifyÚ_PADDINGÚ_SHA256Ú
ValueErrorÚcryptographyÚ
exceptionsÚInvalidSignature)r   ÚmessageÚ	signaturer   r   r   r   2   s   
ÿzRSAVerifier.verifyc                 C   sD   t  |¡}t|v rtj |t¡}| ¡ }| |ƒS t 	|t¡}| |ƒS )ay  Construct an Verifier instance from a public key or public
        certificate string.

        Args:
            public_key (Union[str, bytes]): The public key in PEM format or the
                x509 public key certificate.

        Returns:
            Verifier: The constructed verifier.

        Raises:
            ValueError: If the public key can't be parsed.
        )
r   r   Ú_CERTIFICATE_MARKERr   Úx509Úload_pem_x509_certificateÚ_BACKENDr   r   Úload_pem_public_key)Úclsr   Úpublic_key_dataÚcertÚpubkeyr   r   r   Úfrom_string;   s   
ÿþzRSAVerifier.from_stringN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   Úcopy_docstringr   ÚVerifierr   Úclassmethodr#   r   r   r   r   r   &   s    

r   c                   @   sd   e Zd ZdZddd„Zee ej	¡dd„ ƒƒZ
e ej	¡dd„ ƒZedd	d
„ƒZdd„ Zdd„ ZdS )Ú	RSASignera…  Signs messages with an RSA private key.

    Args:
        private_key (
                cryptography.hazmat.primitives.asymmetric.rsa.RSAPrivateKey):
            The private key to sign with.
        key_id (str): Optional key ID used to identify this private key. This
            can be useful to associate the private key with its associated
            public key or certificate.
    Nc                 C   s   || _ || _d S r	   )Ú_keyÚ_key_id)r   Úprivate_keyÚkey_idr   r   r   r   d   s   
zRSASigner.__init__c                 C   s   | j S r	   )r-   )r   r   r   r   r/   h   s   zRSASigner.key_idc                 C   s   t  |¡}| j |tt¡S r	   )r   r   r,   Úsignr   r   )r   r   r   r   r   r0   m   s   
zRSASigner.signc                 C   s&   t  |¡}tj|dtd�}| ||d�S )al  Construct a RSASigner from a private key in PEM format.

        Args:
            key (Union[bytes, str]): Private key in PEM format.
            key_id (str): An optional key id used to identify the private key.

        Returns:
            google.auth.crypt._cryptography_rsa.RSASigner: The
            constructed signer.

        Raises:
            ValueError: If ``key`` is not ``bytes`` or ``str`` (unicode).
            UnicodeDecodeError: If ``key`` is ``bytes`` but cannot be decoded
                into a UTF-8 ``str``.
            ValueError: If ``cryptography`` "Could not deserialize key data."
        N)ÚpasswordÚbackend)r/   )r   r   r   Úload_pem_private_keyr   )r   Úkeyr/   r.   r   r   r   r#   r   s
   
ÿzRSASigner.from_stringc                 C   s0   | j  ¡ }| jjtjjtjjt 	¡ d�|d< |S )z1Pickle helper that serializes the _key attribute.)ÚencodingÚformatÚencryption_algorithmr,   )
Ú__dict__Úcopyr,   Úprivate_bytesr   ÚEncodingÚPEMÚPrivateFormatÚPKCS8ÚNoEncryption©r   Ústater   r   r   Ú__getstate__Š   s   

ýzRSASigner.__getstate__c                 C   s$   t  |d d¡|d< | j |¡ dS )z3Pickle helper that deserializes the _key attribute.r,   N)r   r3   r8   Úupdater@   r   r   r   Ú__setstate__”   s   zRSASigner.__setstate__r	   )r$   r%   r&   r'   r   Úpropertyr   r(   r   ÚSignerr/   r0   r*   r#   rB   rD   r   r   r   r   r+   X   s    




r+   )r'   Úcryptography.exceptionsr   Úcryptography.hazmatr   Úcryptography.hazmat.primitivesr   r   Ú)cryptography.hazmat.primitives.asymmetricr   Úcryptography.x509Úgoogle.authr   Úgoogle.auth.cryptr   r   Údefault_backendr   ÚPKCS1v15r   ÚSHA256r   r)   r   rF   ÚFromServiceAccountMixinr+   r   r   r   r   Ú<module>   s   2