Ë
    ³Œjõ  ã            	       óÌ   — d Z ddlZddlZddlZddlZddlmZ ddlmZ ddl	m
Z
 ddlZ ej                  e«      Z	 ddededee   d	ej"                  fd
„Zd„ Zd„ Z	 dd„Zdd„Zy)z<
Helper functions for mTLS in async for discovery of certs.
é    N)ÚOptional)Ú
exceptions)Úsecure_cert_key_pathsÚ
cert_bytesÚ	key_bytesÚ
passphraseÚreturnc                 óx  — 	 t        | ||¬«      5 \  }}}t        j                  t        j                  j                  «      }|r|}|j                  |||¬«       |cddd«       S # 1 sw Y   yxY w# t        j                  t        t        t        t        t        f$ r}t        j                  d«      |‚d}~ww xY w)a  Creates an SSLContext with the given client certificate and key.
    This function writes the certificate and key to temporary files so that
    ssl.create_default_context can load them, as the ssl module requires
    file paths for client certificates. These temporary files are deleted
    immediately after the SSL context is created.
    Args:
        cert_bytes (bytes): The client certificate content in PEM format.
        key_bytes (bytes): The client private key content in PEM format.
        passphrase (Optional[bytes]): The passphrase for the private key, if any.
    Returns:
        ssl.SSLContext: The configured SSL context with client certificate.

    Raises:
        google.auth.exceptions.TransportError: If there is an error loading the certificate.
    )r   )ÚcertfileÚkeyfileÚpasswordNz3Failed to load client certificate and key for mTLS.)r   ÚsslÚcreate_default_contextÚPurposeÚSERVER_AUTHÚload_cert_chainÚSSLErrorÚOSErrorÚIOErrorÚ
ValueErrorÚRuntimeErrorÚ	TypeErrorr   ÚTransportError)	r   r   r   Ú	cert_pathÚkey_pathÚpassphrase_valÚcontextr   Úexcs	            úh/var/www/html/Fitness-lenito-AI-main/venv/lib/python3.12/site-packages/google/auth/aio/transport/mtls.pyÚmake_client_cert_ssl_contextr        s­   € ð$Ü" :¨yÀZÕPñ U
ØØØä×0Ñ0´·±×1HÑ1HÓIˆGÙØ)�Ø×'Ñ'Ø&Ø$Ø%ð (ô ð
 ÷ Q×PÒPûô �L‰Lœ'¤7¬J¼ÄiÐPò Ü×'Ñ'ØAó
àð	ûðús5   ‚A1 �AA%Á	A1 Á%A.Á*A1 Á.A1 Á1-B9ÂB4Â4B9c              ‡   óÌ   K  — 	 t        j                  | g|¢­Ž ƒ d{  –—† S 7 Œ# t        $ r4 t        j                  «       } |j                  d| g|¢­Ž ƒ d{  –—†7  cY S w xY w­w)zŸRun a blocking function in an executor to avoid blocking the event loop.

    This implements the non-blocking execution strategy for disk I/O operations.
    N)ÚasyncioÚ	to_threadÚAttributeErrorÚget_running_loopÚrun_in_executor)ÚfuncÚargsÚloops      r   Ú_run_in_executorr*   G   sc   è ø€ ð
=ä×&Ñ& tÐ3¨dÒ3×3Ð3Ð3ùÜò =ä×'Ñ'Ó)ˆØ)�T×)Ñ)¨$°Ð<°tÒ<×<Ð<Ò<ð=üs=   ‚A$„$ �"ž$ ¡A$¢$ ¤4A!ÁAÁA!ÁA$Á A!Á!A$c                  óž   — t         j                  j                  j                  j	                  d¬«      st        j                  d«      ‚d„ } | S )a˜  Get a callback which returns the default client SSL credentials.

    Returns:
        Awaitable[Callable[[], Tuple[bytes, bytes]]]: A callback which returns the default
            client certificate bytes and private key bytes, both in PEM format.

    Raises:
        google.auth.exceptions.DefaultClientCertSourceError: If the default
            client SSL credentials don't exist or are malformed.
    F)Úinclude_context_awarez(Default client cert source doesn't existc               “   ó¬   K  — 	 t        «       ƒ d {  –—† \  } }}||fS 7 Œ# t        t        t        f$ r}t	        j
                  |«      }||‚d }~ww xY w­w©N)Úget_client_cert_and_keyr   r   r   r   ÚMutualTLSChannelError)Ú_r   r   Ú
caught_excÚnew_excs        r   Úcallbackz,default_client_cert_source.<locals>.callbackg   s^   è ø€ ð	*Ü-DÓ-F×'FÑ$ˆAˆz˜9ð
 ˜9Ð$Ð$ð (GùÜœ¤zÐ2ò 	*Ü ×6Ñ6°zÓBˆGØ˜zÐ)ûð	*üs0   ‚A„  ‘’  šAž   A´AÁAÁA)ÚgoogleÚauthÚ	transportÚmtlsÚhas_default_client_cert_sourcer   r0   )r4   s    r   Údefault_client_cert_sourcer:   U   sO   € ô �;‰;× Ñ ×%Ñ%×DÑDØ#ð Eô ô ×.Ñ.Ø6ó
ð 	
ò%ð €Oó    c              ƒ   ó¬   K  — t        t        j                  j                  j                  j
                  | d«      ƒ d{  –—† \  }}|r|rd||dfS y7 Œ­w)a×  Returns the client side certificate, private key and passphrase.

    We look for certificates and keys with the following order of priority:
        1. Certificate and key specified by certificate_config.json.
               Currently, only X.509 workload certificates are supported.

    Args:
        certificate_config_path (str): The certificate_config.json file path.

    Returns:
        Tuple[bool, bytes, bytes, bytes]:
            A boolean indicating if cert, key and passphrase are obtained, the
            cert bytes and key bytes both in PEM format, and passphrase bytes.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert, key and passphrase.
    FNT)FNNN)r*   r5   r6   r7   Ú_mtls_helperÚ_get_workload_cert_and_key)Úcertificate_config_pathÚcertÚkeys      r   Úget_client_ssl_credentialsrB   s   sX   è ø€ ô. 'Ü�‰×Ñ×*Ñ*×EÑEØØó÷ �I€Dˆ#ñ ‘Ø�T˜3 Ð$Ð$à"ðús   ‚=A¿AÁ Ac              ƒ   ó¶   K  — | r4 | «       }t        j                  |«      r|ƒ d{  –—† \  }}n|\  }}d||fS t        «       ƒ d{  –—† \  }}}}|||fS 7 Œ.7 Œ­w)a  Returns the client side certificate and private key. The function first
    tries to get certificate and key from client_cert_callback; if the callback
    is None or doesn't provide certificate and key, the function tries application
    default SSL credentials.

    Args:
        client_cert_callback (Optional[Callable[[], (bytes, bytes)]]): An
            optional callback which returns client certificate bytes and private
            key bytes both in PEM format.

    Returns:
        Tuple[bool, bytes, bytes]:
            A boolean indicating if cert and key are obtained, the cert bytes
            and key bytes both in PEM format.

    Raises:
        google.auth.exceptions.ClientCertError: if problems occurs when getting
            the cert and key.
    NT)ÚinspectÚisawaitablerB   )Úclient_cert_callbackÚresultr@   rA   Úhas_certr1   s         r   r/   r/   –   sn   è ø€ ñ( Ù%Ó'ˆÜ×Ñ˜vÔ&Ø$Ÿ‰IˆD‘#à‰IˆD�#Ø�T˜3ˆÐä#=Ó#?×?Ñ€Hˆd�C˜Ø�T˜3ÐÐð %øð
 @ús!   ‚$A¦A§AÁAÁAÁAr.   )Ú__doc__r"   rD   Úloggingr   Útypingr   Úgoogle.authr   Ú"google.auth.transport._mtls_helperr   Úgoogle.auth.transport.mtlsr5   Ú	getLoggerÚ__name__Ú_LOGGERÚbytesÚ
SSLContextr    r*   r:   rB   r/   © r;   r   Ú<module>rU      s…   ðñó Û Û Û 
Ý å "Ý DÛ !à
ˆ'×
Ñ
˜HÓ
%€ð HLñ$Øð$Ø"'ð$Ø5=¸e±_ð$à‡^�^ó$òN=òð> !ó #ôFr;   