Ë
    ³ŒjÏ6  ã                   óø   — d Z ddlZddlZddlZddlZddlZddlZddlmZm	Z	 ddl
Z
ddlmZmZ dZg d¢ZdZdZd	Zd
ZdZ eeeez  z
  ez  «      Zegez  egez  z   Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Z d„ Z!y)z'Helpers for Agent Identity credentials.é    N)ÚquoteÚurlparse)Úenvironment_varsÚ
exceptionsz‰The cryptography library is required for certificate-based authentication.Please install it with `pip install google-auth[cryptography]`.)z+^agents\.global\.org-\d+\.system\.id\.goog$z,^agents\.global\.proj-\d+\.system\.id\.goog$z3^agents-nonprod\.global\.org-\d+\.system\.id\.goog$z4^agents-nonprod\.global\.proj-\d+\.system\.id\.goog$z=/var/run/secrets/workload-spiffe-credentials/certificates.pemé2   gš™™™™™¹?g      à?é   c                 óÄ   — | sy	 t        j                  | «      }t        j                  |j                  «      xr |j                  dkD  S # t
        $ r ‚ t        $ r Y yw xY w)z=Checks if a file exists, is a regular file, and is not empty.Fr   )ÚosÚstatÚS_ISREGÚst_modeÚst_sizeÚPermissionErrorÚOSError)ÚpathÚsts     úk/var/www/html/Fitness-lenito-AI-main/venv/lib/python3.12/site-packages/google/auth/_agent_identity_utils.pyÚ_is_certificate_file_readyr   ;   sY   € áØð
ô �W‰W�T‹]ˆÜ�|‰|˜BŸJ™JÓ'Ò:¨B¯J©J¸©NÐ:øÜò àÜò Ùðús   …AA
 Á
AÁAc                  ó¨  — t         j                  j                  t        j                  «      } | syt         j
                  j                  t        «      }	 t         j
                  j                  | «      }t         j
                  j                  |«      }t         j
                  j                  ||g«      |k(  }t        | |«      S # t        $ r d}Y Œw xY w)a\  Gets the agent certificate path from the certificate config file.

    The path to the certificate config file is read from the
    GOOGLE_API_CERTIFICATE_CONFIG environment variable. This function
    can optionally trigger polling to handle cases where the environment
    variable is set before the files are available on the filesystem.

    Returns:
        Optional[str]: The path to the agent's certificate file, or None if unavailable.

    Raises:
        google.auth.exceptions.RefreshError: If the certificate config file
            or the certificate file cannot be found after retries.
    NF)r
   ÚenvironÚgetr   ÚGOOGLE_API_CERTIFICATE_CONFIGr   ÚdirnameÚ_WELL_KNOWN_CERT_PATHÚabspathÚ
commonpathÚ
ValueErrorÚ$_get_cert_path_with_optional_polling)Úcert_config_pathÚwell_known_dirÚabs_cert_pathÚabs_well_known_dirÚshould_polls        r   Ú#get_agent_identity_certificate_pathr$   L   s¯   € ô —z‘z—~‘~Ô&6×&TÑ&TÓUÐáØô —W‘W—_‘_Ô%:Ó;€NðÜŸ™Ÿ™Ð(8Ó9ˆÜŸW™WŸ_™_¨^Ó<Ðä�G‰G×ÑÐ 2°MÐBÓCØ!ñ"ð 	ô 0Ð0@À+ÓNÐNøô ò ØŠðús   ÁA"C ÃCÃCc                 ó‚  — d}d}t         D ]^  }	 t        | «      }|€ yt        |«      r|c S |s y|s"t        j                  d|› dt
        › d�«       d}t        j                   |«       Œ` t#        j$                  dt        j&                  › d�«      ‚# t        $ r$}t        j                  d|› d�«       Y d}~ yd}~wt        t        t        f$ rl}t        j                  j                  | «      rY d}~ y|sY d}~ y|s3t        j                  d	|› d
t        j                  › dt
        › d�«       d}Y d}~Œäd}~ww xY w)ai  Gets the certificate path, optionally polling until it is ready.

    Args:
        cert_config_path (str): The path to the certificate configuration file.
        should_poll (bool): If True, the function will poll for the file and
            certificate to be ready. If False, it will check only once and
            return early if they are not immediately available.

    Returns:
        str: The path to the certificate file, or None if unavailable.

    Raises:
        google.auth.exceptions.RefreshError: If the certificate config file
            or the certificate file cannot be found after retries.
    FNzCertificate file not ready at z(. Retrying until startup timeout (up to z seconds total)...TzIPermission denied when accessing certificate config or certificate file: úM. Token binding protection cannot be enabled. Falling back to unbound tokens.z1Certificate config file not found or incomplete: z (from z> environment variable). Retrying until startup timeout (up to zšCertificate config or certificate file not found after multiple retries. Token binding protection is failing. You can turn off this protection by setting z) to false to fall back to unbound tokens.)Ú_POLLING_INTERVALSÚ_parse_cert_path_from_configr   ÚwarningsÚwarnÚ_TOTAL_TIMEOUTr   ÚIOErrorr   ÚKeyErrorr
   r   Úexistsr   r   ÚtimeÚsleepr   ÚRefreshErrorÚ7GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES)r   r#   Úhas_logged_config_warningÚhas_logged_cert_warningÚintervalÚ	cert_pathÚes          r   r   r   s   sf  € ð  !&ÐØ#Ðç&ˆð*	1Ü4Ð5EÓFˆIàÐ Ùä)¨)Ô4Ø Ò ñ áá*Ü—‘Ø4°Y°KÐ?gÔhvÐgwð  xJð  Kôð +/Ð'ô6 	�
‰
�8Õð] 'ô` ×
!Ñ
!ð	\ä×SÑSÐ
Tð U*ð	*óð øô7 ò 	Ü�M‰MØ[Ð\]Ð[^ð _^ð ^ôõ ûÜœ¤XÐ.ò 	1Ü�w‰w�~‰~Ð.Ô/õ áåá,Ü—‘ØGÈÀsÈ'Ü'×EÑEÐFð G=Ü=KÐ<LÐL^ð`ôð
 -1Ð)ÿøð!	1ús>   �BžB­B±$BÂ	D>ÂB;Â;D>ÃD9Ã7D9Ã?5D9Ä9D>c                 ó2  — ddl }t        | dd¬«      5 }|j                  |«      }ddd«       t        t        «      r|j                  d«      nd}t        |t        «      r|j                  d«      nd}t        |t        «      rd|vry|d   S # 1 sw Y   ŒixY w)	a	  Reads the cert config file and returns the cert_path.

    Args:
        cert_config_path (str): The path to the certificate configuration file.

    Returns:
        Optional[str]: The path to the certificate file, or None if not found
            in the config.

    Raises:
        IOError: If the certificate config file cannot be read.
        ValueError: If the certificate config file contains invalid JSON.
        KeyError: If the certificate config file does not contain the
            expected structure.
    r   NÚrúutf-8)ÚencodingÚcert_configsÚworkloadr6   )ÚjsonÚopenÚloadÚ
isinstanceÚdictr   )r   r>   ÚfÚcert_configr<   Úworkload_configs         r   r(   r(   ¾   s�   € ó  ä	Ð ¨gÕ	6¸!Ø—i‘i “lˆ÷ 
7ô ,6°kÄ4Ô+Hˆ�‰˜Ô'Èdð ô )3°<ÄÔ(Fˆ×Ñ˜Ô$ÈDð ô �o¤tÔ,°À?Ñ0RØà˜;Ñ'Ð'÷ 
7Ð	6ús   “BÂBc                  ó´  — t         j                  j                  t        j                  d«      j                  «       dk(  } | ryddlm} |j                  «       }|du ryt        «       }|sy	 t        |d«      5 }|j                  «       }ddd«       t        «      S # 1 sw Y   ŒxY w# t        $ r&}t        j                  d|› d	|› d
�«       Y d}~yd}~ww xY w)a1  Gets and parses the agent identity certificate if not opted out.

    Checks if the user has opted out of certificate-bound tokens. If not,
    it gets the certificate path, reads the file, and parses it.

    Returns:
        The parsed certificate object if found and not opted out, otherwise None.
    ÚtrueÚfalseNr   ©Ú_mtls_helperFÚrbz2Failed to read agent identity certificate file at z: r&   )r
   r   r   r   r2   ÚlowerÚgoogle.auth.transportrJ   Ú_check_use_client_cert_envr$   r?   Úreadr   r)   r*   Úparse_certificate)Úis_opted_outrJ   Úenv_overrider6   Ú	cert_fileÚ
cert_bytesr7   s          r   Ú(get_and_parse_agent_identity_certificaterU   à   sÜ   € ô 	�
‰
�‰Ü×TÑTØó	
÷ ‰%‹'Øñ		ð ñ Øõ 3à×:Ñ:Ó<€LØ�uÑØä3Ó5€IÙØðÜ�)˜TÔ" iØ"Ÿ™Ó)ˆJ÷ #ô ˜ZÓ(Ð(÷ #Ð"ûäò Ü�‰Ø@ÀÀÈ2ÈaÈSð QZð Zô	
ô ûðús0   Á,B( Á8BÂ	B( ÂB%Â!B( Â(	CÂ1CÃCc                 ót   — 	 ddl m} |j                  | «      S # t        $ r}t        t        «      |‚d}~ww xY w)zÄParses a PEM-encoded certificate.

    Args:
        cert_bytes (bytes): The PEM-encoded certificate bytes.

    Returns:
        cryptography.x509.Certificate: The parsed certificate object.
    r   ©Úx509N)ÚcryptographyrX   Úload_pem_x509_certificateÚImportErrorÚCRYPTOGRAPHY_NOT_FOUND_ERROR)rT   rX   r7   s      r   rP   rP     s9   € ð?Ý%à×-Ñ-¨jÓ9Ð9øÜò ?ÜÔ6Ó7¸QÐ>ûð?ús   ‚ ™	7¢2²7c                 óÄ  — 	 ddl m} ddlm} 	 | j                  j                  |j                  «      }|j                  j                  |j                  «      }|D ]M  }t        |«      }|j                  dk(  sŒ|j                  }t        D ]  }t        j                   ||«      sŒ  y ŒO y# |j                  $ r Y yw xY w# t"        $ r}	t#        t$        «      |	‚d}	~	ww xY w)aš  Checks if a certificate is an Agent Identity certificate.

    This is determined by checking the Subject Alternative Name (SAN) for a
    SPIFFE ID with a trust domain matching Agent Identity patterns.

    Args:
        cert (cryptography.x509.Certificate): The parsed certificate object.

    Returns:
        bool: True if the certificate is an Agent Identity certificate,
            False otherwise.
    r   rW   )ÚExtensionOIDFÚspiffeTN)rY   rX   Úcryptography.x509.oidr^   Ú
extensionsÚget_extension_for_oidÚSUBJECT_ALTERNATIVE_NAMEÚExtensionNotFoundÚvalueÚget_values_for_typeÚUniformResourceIdentifierr   ÚschemeÚnetlocÚ,_AGENT_IDENTITY_SPIFFE_TRUST_DOMAIN_PATTERNSÚreÚmatchr[   r\   )
ÚcertrX   r^   ÚextÚurisÚuriÚ
parsed_uriÚtrust_domainÚpatternr7   s
             r   Ú_is_agent_identity_certificatert     sÑ   € ð?Ý%Ý6ð	Ø—/‘/×7Ñ7Ø×5Ñ5óˆCð
 �y‰y×,Ñ,¨T×-KÑ-KÓLˆãˆCÜ! #›ˆJØ× Ñ  HÓ,Ø)×0Ñ0�ßK�GÜ—x‘x ¨Õ6Ú#ñ  Lð	 ð øð ×%Ñ%ò 	Ùð	ûô ò ?ÜÔ6Ó7¸QÐ>ûð?úsL   ‚C �%B, ´AC Á9+C Â%C Â(C Â,B>Â;C Â=B>Â>C Ã	CÃ
CÃCc                 ób  — 	 ddl m} | j                  |j                  j                  «      }t        j                  |«      j                  «       }t        j                  |«      j                  d«      }|j                  d«      }t        |«      S # t        $ r}t        t        «      |‚d}~ww xY w)a  Calculates the URL-encoded, unpadded, base64-encoded SHA256 hash of a
    DER-encoded certificate.

    Args:
        cert (cryptography.x509.Certificate): The parsed certificate object.

    Returns:
        str: The URL-encoded, unpadded, base64-encoded SHA256 fingerprint.
    r   )Úserializationr:   Ú=N)Úcryptography.hazmat.primitivesrv   Úpublic_bytesÚEncodingÚDERÚhashlibÚsha256ÚdigestÚbase64Ú	b64encodeÚdecodeÚrstripr   r[   r\   )rm   rv   Úder_certÚfingerprintÚbase64_fingerprintÚunpadded_base64_fingerprintr7   s          r   Ú!calculate_certificate_fingerprintr‡   C  s–   € ð?Ý@à×$Ñ$ ]×%;Ñ%;×%?Ñ%?Ó@ˆÜ—n‘n XÓ.×5Ñ5Ó7ˆô $×-Ñ-¨kÓ:×AÑAÀ'ÓJÐØ&8×&?Ñ&?ÀÓ&DÐ#ÜÐ0Ó1Ð1øÜò ?ÜÔ6Ó7¸QÐ>ûð?ús   ‚BB Â	B.ÂB)Â)B.c                 óØ   — t        | «      }t        j                  j                  t        j
                  d«      j                  «       dk(  }|r|syddlm} |j                  «       }|du ryy)a‡  Determines if a bound token should be requested.

    This is based on the GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES
    environment variable and whether the certificate is an agent identity cert.

    Args:
        cert (cryptography.x509.Certificate): The parsed certificate object.

    Returns:
        bool: True if a bound token should be requested, False otherwise.
    rG   Fr   rI   T)
rt   r
   r   r   r   r2   rL   rM   rJ   rN   )rm   Úis_agent_certÚis_opted_inrJ   rR   s        r   Úshould_request_bound_tokenr‹   ^  sk   € ô 3°4Ó8€Mä
�
‰
�‰Ü×TÑTØó	
÷ ‰%‹'Øñ		ð ñ ™kØõ 3à×:Ñ:Ó<€LØ�uÑØàó    c                 óL   — | rt        | «      }t        |«      }|S t        d«      ‚)z2Returns the fingerprint of the cached certificate.z"mTLS connection is not configured.)rP   r‡   r   )Úcached_certÚcert_objÚcached_cert_fingerprints      r   Úget_cached_cert_fingerprintr‘     s0   € áÜ$ [Ó1ˆÜ"CÀHÓ"MÐð #Ð"ô Ð=Ó>Ð>rŒ   )"Ú__doc__r   r|   r
   rk   r   r/   Úurllib.parser   r   r)   Úgoogle.authr   r   r\   rj   r   Ú_FAST_POLL_CYCLESÚ_FAST_POLL_INTERVALÚ_SLOW_POLL_INTERVALr+   ÚintÚ_SLOW_POLL_CYCLESr'   r   r$   r   r(   rU   rP   rt   r‡   r‹   r‘   © rŒ   r   Ú<module>r›      sØ   ðñ .ã Û Û 	Û 	Û Û ß (Û ç 4ðFð ò0Ð ,ð XÐ ð Ð ØÐ ØÐ Ø€ñ ØÐ(Ð+>Ñ>Ñ?ÐCVÑVóÐ ð +Ð+Ð.?Ñ?ØÐÐ-Ñ-ñÐ ò
ò"$OòNHòV(òD*)òZ?ò""?òJ?ò6óB#rŒ   