Ë
    ³ŒjÃ  ã                   óž  — d Z ddlZddlmZ ddlZddlmZ ddlmZ ddlm	Z	 ddlm
Z
 ddlmZ ddlmZ ej                  ej                  ej                   ej"                  hZd	gZ eed
«      r! ej*                  «       rde	j,                  › �Znde	j,                  › �Zde› d�Zedz   Zedz   Zedz   Zedz   Z G d„ de
j:                  «      Zy)zÇTools for using the Google `Cloud Identity and Access Management (IAM)
API`_'s auth-related functionality.

.. _Cloud Identity and Access Management (IAM) API:
    https://cloud.google.com/iam/docs/
é    N)Ú_exponential_backoff)Ú_helpers)Úcredentials)Úcrypt)Ú
exceptions)Ú_mtls_helperz#https://www.googleapis.com/auth/iamÚcheck_use_client_certziamcredentials.mtls.ziamcredentials.zhttps://z!/v1/projects/-/serviceAccounts/{}z:generateAccessTokenz	:signBlobz:signJwtz:generateIdTokenc                   óp   — e Zd ZdZd„ Zd„ Zed„ «       Z ej                  e
j                  «      d„ «       Zy)ÚSignera  Signs messages using the IAM `signBlob API`_.

    This is useful when you need to sign bytes but do not have access to the
    credential's private key file.

    .. _signBlob API:
        https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts
        /signBlob
    c                 ó.   — || _         || _        || _        y)aÝ  
        Args:
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            credentials (google.auth.credentials.Credentials): The credentials
                that will be used to authenticate the request to the IAM API.
                The credentials must have of one the following scopes:

                - https://www.googleapis.com/auth/iam
                - https://www.googleapis.com/auth/cloud-platform
            service_account_email (str): The service account email identifying
                which service account to use to sign bytes. Often, this can
                be the same as the service account email in the given
                credentials.
        N)Ú_requestÚ_credentialsÚ_service_account_email)ÚselfÚrequestr   Úservice_account_emails       úY/var/www/html/Fitness-lenito-AI-main/venv/lib/python3.12/site-packages/google/auth/iam.pyÚ__init__zSigner.__init__J   s   € ð   ˆŒØ'ˆÔØ&;ˆÕ#ó    c                 ó^  — t        j                  |«      }d}t        j                  t        j
                  | j                  j                  «      j                  | j                  «      }ddi}t        j                  dt        j                  |«      j                  d«      i«      j                  d«      }t!        j"                  «       }|D ]Ì  }| j                  j%                  | j&                  |||«       | j'                  ||||¬«      }|j(                  t*        v rŒS|j(                  t,        j.                  k7  r.t1        j2                  dj                  |j4                  «      «      ‚t        j6                  |j4                  j                  d«      «      c S  t1        j2                  d«      ‚)	z(Makes a request to the API signBlob API.ÚPOSTzContent-Typezapplication/jsonÚpayloadzutf-8)ÚurlÚmethodÚbodyÚheadersz&Error calling the IAM signBlob API: {}z#exhausted signBlob endpoint retries)r   Úto_bytesÚ_IAM_SIGN_ENDPOINTÚreplacer   ÚDEFAULT_UNIVERSE_DOMAINr   Úuniverse_domainÚformatr   ÚjsonÚdumpsÚbase64Ú	b64encodeÚdecodeÚencoder   ÚExponentialBackoffÚbefore_requestr   ÚstatusÚIAM_RETRY_CODESÚhttp_clientÚOKr   ÚTransportErrorÚdataÚloads)	r   Úmessager   r   r   r   ÚretriesÚ_Úresponses	            r   Ú_make_signing_requestzSigner._make_signing_request^   s]  € ä×#Ñ# GÓ,ˆàˆÜ ×(Ñ(Ü×/Ñ/°×1BÑ1B×1RÑ1Ró
ç
‰&�×,Ñ,Ó
-ð 	ð "Ð#5Ð6ˆÜ�z‰zØœ×(Ñ(¨Ó1×8Ñ8¸ÓAÐBó
ç
‰&�‹/ð 	ô '×9Ñ9Ó;ˆÛˆAØ×Ñ×,Ñ,¨T¯]©]¸FÀCÈÔQà—}‘}¨°VÀ$ÐPW�}ÓXˆHà�‰¤/Ñ1Øà�‰¤+§.¡.Ò0Ü ×/Ñ/Ø<×CÑCÀHÇMÁMÓRóð ô —:‘:˜hŸm™m×2Ñ2°7Ó;Ó<Ò<ð ô ×'Ñ'Ð(MÓNÐNr   c                  ó   — y)zÏOptional[str]: The key ID used to identify this private key.

        .. warning::
           This is always ``None``. The key ID used by IAM can not
           be reliably determined ahead of time.
        N© )r   s    r   Úkey_idzSigner.key_id|   s   € ð r   c                 óT   — | j                  |«      }t        j                  |d   «      S )NÚ
signedBlob)r6   r%   Ú	b64decode)r   r2   r5   s      r   ÚsignzSigner.sign†   s(   € à×-Ñ-¨gÓ6ˆÜ×Ñ ¨Ñ 6Ó7Ð7r   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r6   Úpropertyr9   r   Úcopy_docstringr   r   r=   r8   r   r   r   r   ?   sK   „ ñò<ò(Oð< ñó ðð €X×Ñ˜UŸ\™\Ó*ñ8ó +ñ8r   r   )rA   r%   Úhttp.clientÚclientr-   r#   Úgoogle.authr   r   r   r   r   Úgoogle.auth.transportr   ÚINTERNAL_SERVER_ERRORÚBAD_GATEWAYÚSERVICE_UNAVAILABLEÚGATEWAY_TIMEOUTr,   Ú
_IAM_SCOPEÚhasattrr	   r    Ú_IAM_DOMAINÚ_IAM_BASE_URLÚ_IAM_ENDPOINTr   Ú_IAM_SIGNJWT_ENDPOINTÚ_IAM_IDTOKEN_ENDPOINTr   r8   r   r   Ú<module>rS      só   ðñó Ý !Û å ,Ý  Ý #Ý Ý "Ý .ð ×%Ñ%Ø×ÑØ×#Ñ#Ø×Ñð	€ð 4Ð4€
ñ ˆLÐ1Ô2Ø*ˆ×*Ñ*Ô,ð )¨×)LÑ)LÐ(MÐN�Kà# K×$GÑ$GÐ#HÐI€Kð ˜;˜-Ð'JÐK€ð Ð 6Ñ6€Ø" [Ñ0Ð Ø%¨
Ñ2Ð Ø%Ð(:Ñ:Ð ôJ8ˆU�\‰\õ J8r   