o
    í6WjÃ  ã                   @   sð   d Z ddlZddlmZ ddlZddlmZ ddlmZ ddlm	Z	 ddlm
Z
 ddlmZ ddlmZ ejejejejhZd	gZeed
ƒrQe ¡ rQde	j› �Znde	j› �Zde› d�Zed Zed Zed Zed ZG dd„ de
jƒZdS )zÇTools for using the Google `Cloud Identity and Access Management (IAM)
API`_'s auth-related functionality.

.. _Cloud Identity and Access Management (IAM) API:
    https://cloud.google.com/iam/docs/
é    N)Ú_exponential_backoff)Ú_helpers)Úcredentials)Úcrypt)Ú
exceptions)Ú_mtls_helperz#https://www.googleapis.com/auth/iamÚcheck_use_client_certziamcredentials.mtls.ziamcredentials.zhttps://z!/v1/projects/-/serviceAccounts/{}z:generateAccessTokenz	:signBlobz:signJwtz:generateIdTokenc                   @   s@   e Zd ZdZdd„ Zdd„ Zedd„ ƒZe 	e
j¡dd	„ ƒZd
S )ÚSignera  Signs messages using the IAM `signBlob API`_.

    This is useful when you need to sign bytes but do not have access to the
    credential's private key file.

    .. _signBlob API:
        https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts
        /signBlob
    c                 C   s   || _ || _|| _dS )aÝ  
        Args:
            request (google.auth.transport.Request): The object used to make
                HTTP requests.
            credentials (google.auth.credentials.Credentials): The credentials
                that will be used to authenticate the request to the IAM API.
                The credentials must have of one the following scopes:

                - https://www.googleapis.com/auth/iam
                - https://www.googleapis.com/auth/cloud-platform
            service_account_email (str): The service account email identifying
                which service account to use to sign bytes. Often, this can
                be the same as the service account email in the given
                credentials.
        N)Ú_requestÚ_credentialsÚ_service_account_email)ÚselfÚrequestr   Úservice_account_email© r   ú^/home/esfera/Documents/content_generation/venv/lib/python3.10/site-packages/google/auth/iam.pyÚ__init__J   s   
zSigner.__init__c           	      C   sÐ   t  |¡}d}t tj| jj¡ | j	¡}ddi}t
 dt |¡ d¡i¡ d¡}t ¡ }|D ]4}| j | j|||¡ | j||||d�}|jtv rIq.|jtjkrXt d |j¡¡‚t
 |j d¡¡  S t d¡‚)	z(Makes a request to the API signBlob API.ÚPOSTzContent-Typezapplication/jsonÚpayloadzutf-8)ÚurlÚmethodÚbodyÚheadersz&Error calling the IAM signBlob API: {}z#exhausted signBlob endpoint retries)r   Úto_bytesÚ_IAM_SIGN_ENDPOINTÚreplacer   ÚDEFAULT_UNIVERSE_DOMAINr   Úuniverse_domainÚformatr   ÚjsonÚdumpsÚbase64Ú	b64encodeÚdecodeÚencoder   ÚExponentialBackoffÚbefore_requestr
   ÚstatusÚIAM_RETRY_CODESÚhttp_clientÚOKr   ÚTransportErrorÚdataÚloads)	r   Úmessager   r   r   r   ÚretriesÚ_Úresponser   r   r   Ú_make_signing_request^   s2   

ÿþÿþ

ÿ
zSigner._make_signing_requestc                 C   s   dS )zÏOptional[str]: The key ID used to identify this private key.

        .. warning::
           This is always ``None``. The key ID used by IAM can not
           be reliably determined ahead of time.
        Nr   )r   r   r   r   Úkey_id|   s   zSigner.key_idc                 C   s   |   |¡}t |d ¡S )NÚ
signedBlob)r2   r!   Ú	b64decode)r   r.   r1   r   r   r   Úsign†   s   
zSigner.signN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r2   Úpropertyr3   r   Úcopy_docstringr   r	   r6   r   r   r   r   r	   ?   s    


	r	   )r:   r!   Úhttp.clientÚclientr)   r   Úgoogle.authr   r   r   r   r   Úgoogle.auth.transportr   ÚINTERNAL_SERVER_ERRORÚBAD_GATEWAYÚSERVICE_UNAVAILABLEÚGATEWAY_TIMEOUTr(   Ú
_IAM_SCOPEÚhasattrr   r   Ú_IAM_DOMAINÚ_IAM_BASE_URLÚ_IAM_ENDPOINTr   Ú_IAM_SIGNJWT_ENDPOINTÚ_IAM_IDTOKEN_ENDPOINTr	   r   r   r   r   Ú<module>   s8   üÿþ