o
    Þ­j‘  ã                	   @   sÈ   d Z ddlZddlZddlZddlZddlZddlZddlmZ ddl	m
Z
 ddlZddlZe e¡Zejdefdd„ƒZ	dded	ed
ee dejfdd„Zdd„ Zdd„ Z	ddd„Zddd„ZdS )z<
Helper functions for mTLS in async for discovery of certs.
é    N)ÚOptional)Ú
exceptionsÚcontentc              	   c   s†   � t  ¡ \}}z.t |d¡�}| | ¡ W d  ƒ n1 sw   Y  |V  W tj |¡r4t |¡ dS dS tj |¡rBt |¡ w w )zµCreates a temporary file with the given content.

    Args:
        content (bytes): The content to write to the file.

    Yields:
        str: The path to the temporary file.
    ÚwbN)ÚtempfileÚmkstempÚosÚfdopenÚwriteÚpathÚexistsÚremove)r   ÚfdÚ	file_pathÚf© r   ú[/var/www/html/CropPilot/venv/lib/python3.10/site-packages/google/auth/aio/transport/mtls.pyÚ_create_temp_file"   s   €ÿÿÿr   Ú
cert_bytesÚ	key_bytesÚ
passphraseÚreturnc                 C   sº   t | ƒ�O}t |ƒ�:}z t tjj¡}|j|||d� |W W  d  ƒ W  d  ƒ S  tjttt	t
fyB } zt d¡|‚d}~ww 1 sFw   Y  W d  ƒ dS 1 sVw   Y  dS )a  Creates an SSLContext with the given client certificate and key.
    This function writes the certificate and key to temporary files so that
    ssl.create_default_context can load them, as the ssl module requires
    file paths for client certificates. These temporary files are deleted
    immediately after the SSL context is created.
    Args:
        cert_bytes (bytes): The client certificate content in PEM format.
        key_bytes (bytes): The client private key content in PEM format.
        passphrase (Optional[bytes]): The passphrase for the private key, if any.
    Returns:
        ssl.SSLContext: The configured SSL context with client certificate.

    Raises:
        google.auth.exceptions.TransportError: If there is an error loading the certificate.
    )ÚcertfileÚkeyfileÚpasswordNz3Failed to load client certificate and key for mTLS.)r   ÚsslÚcreate_default_contextÚPurposeÚSERVER_AUTHÚload_cert_chainÚSSLErrorÚOSErrorÚIOErrorÚ
ValueErrorÚRuntimeErrorr   ÚTransportError)r   r   r   Ú	cert_pathÚkey_pathÚcontextÚexcr   r   r   Úmake_client_cert_ssl_context8   s(   ÿÿø	ÿþ€ÿ4÷r*   c                 Ç   sR   �zt j| g|¢R Ž I dH W S  ty(   t  ¡ }|jd| g|¢R Ž I dH  Y S w )zŸRun a blocking function in an executor to avoid blocking the event loop.

    This implements the non-blocking execution strategy for disk I/O operations.
    N)ÚasyncioÚ	to_threadÚAttributeErrorÚget_running_loopÚrun_in_executor)ÚfuncÚargsÚloopr   r   r   Ú_run_in_executorY   s   €ýr3   c                  C   s(   t jjjjdd�st d¡‚dd„ } | S )a˜  Get a callback which returns the default client SSL credentials.

    Returns:
        Awaitable[Callable[[], Tuple[bytes, bytes]]]: A callback which returns the default
            client certificate bytes and private key bytes, both in PEM format.

    Raises:
        google.auth.exceptions.DefaultClientCertSourceError: If the default
            client SSL credentials don't exist or are malformed.
    F)Úinclude_context_awarez(Default client cert source doesn't existc               
   Ó   sN   �zt ƒ I d H \} }}W ||fS  tttfy& } zt |¡}||‚d }~ww ©N)Úget_client_cert_and_keyr!   r$   r#   r   ÚMutualTLSChannelError)Ú_r   r   Ú
caught_excÚnew_excr   r   r   Úcallbacky   s   €ü
€þz,default_client_cert_source.<locals>.callback)ÚgoogleÚauthÚ	transportÚmtlsÚhas_default_client_cert_sourcer   r7   )r;   r   r   r   Údefault_client_cert_sourceg   s   
ÿÿ	rA   c                 Ã   s8   �t tjjjj| dƒI dH \}}|r|rd||dfS dS )a×  Returns the client side certificate, private key and passphrase.

    We look for certificates and keys with the following order of priority:
        1. Certificate and key specified by certificate_config.json.
               Currently, only X.509 workload certificates are supported.

    Args:
        certificate_config_path (str): The certificate_config.json file path.

    Returns:
        Tuple[bool, bytes, bytes, bytes]:
            A boolean indicating if cert, key and passphrase are obtained, the
            cert bytes and key bytes both in PEM format, and passphrase bytes.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert, key and passphrase.
    FNT)FNNN)r3   r<   r=   r>   Ú_mtls_helperÚ_get_workload_cert_and_key)Úcertificate_config_pathÚcertÚkeyr   r   r   Úget_client_ssl_credentials…   s   €
ýrG   c                 Ã   sb   �| r"| ƒ }z	|I dH \}}W n t y   |\}}Y nw d||fS tƒ I dH \}}}}|||fS )a  Returns the client side certificate and private key. The function first
    tries to get certificate and key from client_cert_callback; if the callback
    is None or doesn't provide certificate and key, the function tries application
    default SSL credentials.

    Args:
        client_cert_callback (Optional[Callable[[], (bytes, bytes)]]): An
            optional callback which returns client certificate bytes and private
            key bytes both in PEM format.

    Returns:
        Tuple[bool, bytes, bytes]:
            A boolean indicating if cert and key are obtained, the cert bytes
            and key bytes both in PEM format.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert and key.
    NT)Ú	TypeErrorrG   )Úclient_cert_callbackÚresultrE   rF   Úhas_certr8   r   r   r   r6   ¨   s   €ÿ

r6   r5   )Ú__doc__r+   Ú
contextlibÚloggingr   r   r   Útypingr   Úgoogle.authr   Ú"google.auth.transport._mtls_helperr<   Úgoogle.auth.transport.mtlsÚ	getLoggerÚ__name__Ú_LOGGERÚcontextmanagerÚbytesr   Ú
SSLContextr*   r3   rA   rG   r6   r   r   r   r   Ú<module>   s:   
ÿÿÿÿ
þ!
ÿ#